Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec1844d4b1a0a93b…

MALICIOUS

PDF

152.9 KB Created: 2012-11-24 16:51:42 +01:00 Authoring application: Adobe LiveCycle Designer ES 9.0 (via Adobe LiveCycle Designer ES 9.0; modified using iText 5.0.6 (c) 1T3XT BVBA) First seen: 2015-09-30
MD5: 95cf4ce39cf5f59c4cb8612ad5678080 SHA-1: 39fa5b3c72f3b4b1f846e80ca57f906c790b1625 SHA-256: ec1844d4b1a0a93b97259c01e5404fad34326b742f52d3b5ecc637bb2d7a4550
94 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file exhibits multiple indicators of malicious intent, including embedded JavaScript streams and embedded script payloads. The presence of XFA forms and AcroForm buttons suggests an attempt to create an interactive lure. The embedded JavaScript, specifically javascript_obj0133_000.js and javascript_obj0134_001.js, is the primary mechanism for executing malicious code, likely downloading and executing a second-stage payload. The document body was not parsable, limiting further analysis of the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6391

Heuristics 8

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocsp.verisign.com0 Referenced by PDF JavaScript
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/Referenced by PDF JavaScript
    • http://ns.adobe.com/pdf/1.3/Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/mm/Referenced by PDF JavaScript
    • http://purl.org/dc/elements/1.1/Referenced by PDF JavaScript
    • http://ns.adobe.com/xfa/promoted-desc/Referenced by PDF JavaScript
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/3.0/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://www.kb.cz/ToDoReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.5/Referenced by PDF JavaScript
    • http://ns.adobe.com/xdp/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/3.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.7/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.1/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
    • http://crl.verisign.com/tss-ca.crl0Referenced by PDF JavaScript
    • http://crl.verisign.com/ThawteTimestampingCA.crl0Referenced by PDF JavaScript
    • https://www.verisign.com/rpaReferenced by PDF JavaScript
    • http://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0DReferenced by PDF JavaScript
    • https://www.verisign.com/rpa0Referenced by PDF JavaScript
    • http://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0Referenced by PDF JavaScript
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlReferenced by PDF JavaScript
    • http://ns.adobe.com/xfdf/In PDF document text

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0006.bin pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x4B03 163 bytes
SHA-256: 51886c02f18523c864de9517a248d92d526ae6888aaed7586d0f989b0fa381e8
embedded_file_obj0007.bin pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x4BF2 2405 bytes
SHA-256: 267bc6bcdb8ed6e633f25fa68791bd9ceeb332247a849a3e3bfeee63b6d55c90
embedded_file_obj0008.bin pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x4FE4 2921 bytes
SHA-256: 08cae221857a208d72230ddb7c80fec725beeff56378b5f3454acfed9f8738b1
embedded_file_obj0009.bin pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x5388 1535 bytes
SHA-256: 1715982188cf22e2877bd76c2a70243d16c113fc64cc0c8020610ce5644399c8
embedded_file_obj0010.bin pdf-embedded-file PDF EmbeddedFile object 10 at offset 0x5647 80 bytes
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
embedded_file_obj0011.bin pdf-embedded-file PDF EmbeddedFile object 11 at offset 0x56EF 56 bytes
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
javascript_obj0133_000.js pdf-javascript-stream PDF /JS object 133 at offset 0x7139 1363 bytes
SHA-256: 529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f
Preview script
First 1,000 lines of the extracted script
if (typeof(xfa_installed) == "undefined" || typeof(xfa_version) == "undefined" || xfa_version < 2.8)
{
   if (app.viewerType == "Reader")
   {
      if (ADBE.Reader_Value_Asked != true)
      {
         if (app.viewerVersion < 9.0)
         {
            if (app.alert(ADBE.Reader_string_Need_New_Version_Msg, 1, 1) == 1)
               this.getURL(ADBE.Reader_Value_New_Version_URL + ADBE.SYSINFO, false);
            ADBE.Reader_Value_Asked = true;
         }
         else if (app.alert(ADBE.Viewer_string_Need_New_Version_Msg_Updater, 1, 1) == 1)
            app.findComponent({cType:"Plugin", cName:"XFA", cVer:"2.8"});
      }
   }
   else
   {
      if (ADBE.Viewer_Value_Asked != true)
      {
         if (app.viewerVersion < 7.0)
            app.response({cQuestion: ADBE.Viewer_string_Need_New_Version_Msg_Old, cDefault: ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, cTitle: ADBE.Viewer_string_Title});
		   else if (app.viewerVersion < 9.0)
         {
            if (app.alert(ADBE.Viewer_string_Need_New_Version_Msg, 1, 1) == 1)
               app.launchURL(ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, true);
         }
         else if (app.alert(ADBE.Viewer_string_Need_New_Version_Msg_Updater, 1, 1) == 1)
            app.findComponent({cType:"Plugin", cName:"XFA", cVer:"2.8"});
         ADBE.Viewer_Value_Asked = true;
      }
   }
}
javascript_obj0134_001.js pdf-javascript-stream PDF /JS object 134 at offset 0x7315 902 bytes
SHA-256: e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a
Preview script
First 1,000 lines of the extracted script
if (typeof(ADBE.Reader_Value_Asked) == "undefined")
   ADBE.Reader_Value_Asked = false;
if (typeof(ADBE.Viewer_Value_Asked) == "undefined")
   ADBE.Viewer_Value_Asked = false;
if (typeof(ADBE.Reader_Need_Version) == "undefined" || ADBE.Reader_Need_Version < 9.0)
{
   ADBE.Reader_Need_Version = 9.0;
   ADBE.Reader_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&r=" + ADBE.Reader_Need_Version;
}
if (typeof(ADBE.Viewer_Need_Version) == "undefined" || ADBE.Viewer_Need_Version < 9.0)
{
   ADBE.Viewer_Need_Version = 9.0;
   ADBE.Viewer_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&r=" + ADBE.Viewer_Need_Version;
}
javascript_obj0135_002.js pdf-javascript-stream PDF /JS object 135 at offset 0x746E 1169 bytes
SHA-256: 0ab3d232b2f2272b7039ee3e45d0be78ade06bb45327a799559ad4a592ef5a3d
Preview script
First 1,000 lines of the extracted script
if (typeof(this.ADBE) == "undefined")
   this.ADBE = new Object();
ADBE.LANGUAGE = "ENU";
ADBE.Viewer_string_Title = "Adobe Acrobat";
ADBE.Viewer_string_Update_Desc = "Adobe Interactive Forms Update";
ADBE.Reader_string_Need_New_Version_Msg = "This PDF file requires a newer version of Adobe Reader. Press OK to download the latest version or see your system administrator.";
ADBE.Viewer_string_Need_New_Version_Msg_Old = "This PDF requires a newer version of Acrobat. Copy this URL and paste into your browser or see your sys admin.";
ADBE.Viewer_string_Need_New_Version_Msg = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may display, but may not work properly. Some form elements might not be visible at all. Click OK for more information on obtaining the latest version of Adobe Reader.";
ADBE.Viewer_string_Need_New_Version_Msg_Updater = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may display, but may not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version.";
stream_001_off000001da.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1DA 68830 bytes
SHA-256: 26218a59363e858154224edbe3b445f354c4f341aa36b2291598a74c6c570668
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 long base64-like blob(s).
stream_002_off000039b3.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x39B3 856 bytes
SHA-256: 96f3b95ac590a24927aef9abf434358866dbefb8e8fe69b77b4b3dbd0e90e048
font_00_sfnt_off00007f1e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7F1E 94351 bytes
SHA-256: 1626e6329f65d0d35cdf751ec668ac4b8800d726707d01e7810bb8297d789dee
font_01_cff_off00019727.bin pdf-font-stream PDF embedded font (cff) at offset 0x19727 5600 bytes
SHA-256: 77a0b6c3eea44eabe1eca27c9a3556172dbbac4102a91eebaaca2ab4e62f2f25
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.42, consistent with packed or encrypted content.
font_02_cff_off0001ad79.bin pdf-font-stream PDF embedded font (cff) at offset 0x1AD79 3195 bytes
SHA-256: 19164b1e8011f1baf8fcc59c104786acda8c6d3aadd1a7e0607059d9baecca17