Malicious PDF — malware analysis report

Static analysis result for SHA-256 e95a08d05ca9ba31…

MALICIOUS

PDF

22.5 KB Created: 2013-03-22 14:10:12 +03:00 Authoring application: Adobe Designer 7.0
MD5: af01b33047a4dddacf4ec803d5e98820 SHA-1: b39464649df10f3535c0c0821f9a3def4ae07bbf SHA-256: e95a08d05ca9ba319550ed8b0a30429c62b7d9dd592306e179259879fffbed14
130 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF document contains multiple embedded JavaScript streams and embedded files, flagged by heuristics as potentially malicious. The ML classifier strongly indicates maliciousness. The embedded JavaScript is likely responsible for downloading and executing a secondary payload, as indicated by the 'PDF_EMBEDDED_SCRIPT_PAYLOAD' and 'PDF_XFA_SCRIPT' heuristics. The presence of multiple embedded files suggests a multi-stage attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 8

  • XFA form contains risky executable script high CVE related PDF_XFA_SCRIPT
    PDF embeds an XFA form whose script block contains exploit, submission/launch, or shell-execution primitives. Ordinary LiveCycle print/update scripts are left as generic XFA/JS signals unless stronger behavior is present.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0024.bin
c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
pdf-embedded-file PDF EmbeddedFile object 24 at offset 0x1A91 85 bytes
embedded_file_obj0025.bin
7819f06630520bfd73f8079eece39a31ed650dc5a0392d84cc1a95b60eb179d9
pdf-embedded-file PDF EmbeddedFile object 25 at offset 0x1B43 1520 bytes
embedded_file_obj0026.bin
0e37cddc8a5646ff8fab00ad458ad06c2ede15c2c2e8376d9e8e2ebec16db0b3
pdf-embedded-file PDF EmbeddedFile object 26 at offset 0x1E10 7832 bytes
embedded_file_obj0027.bin
6984ccf51cc4575a4e6ba45c72199e4f534cdbc2b94b3794eb8975121db4cf2b
pdf-embedded-file PDF EmbeddedFile object 27 at offset 0x2DFE 144 bytes
embedded_file_obj0028.bin
f23c9faf054dec10d2ad8550fdb68278f9d8f183a4f16925447bc13736640a65
pdf-embedded-file PDF EmbeddedFile object 28 at offset 0x2EC4 9197 bytes
embedded_file_obj0029.bin
57045217c453d4674a08ad8778674bf199a7989a9505424a1815c016e6bb412f
pdf-embedded-file PDF EmbeddedFile object 29 at offset 0x35E9 212 bytes
javascript_obj0016_000.js
4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
pdf-javascript-stream PDF /JS object 16 at offset 0x131A 870 bytes
javascript_obj0018_001.js
4e139c8b22ec16bd5aa51575c80dec2bbf89b76977a06b68473031a0eb206366
pdf-javascript-stream PDF /JS object 18 at offset 0x149E 2794 bytes
javascript_obj0020_002.js
c876171bd867b66b7671fb337ff9e57d18cd15b43d344cf5a7243821300a408a
pdf-javascript-stream PDF /JS object 20 at offset 0x178D 1528 bytes