Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec1844d4b1a0a93b…

MALICIOUS

PDF

152.9 KB Created: 2012-11-24 16:51:42 +01:00 Authoring application: Adobe LiveCycle Designer ES 9.0 (via Adobe LiveCycle Designer ES 9.0; modified using iText 5.0.6 (c) 1T3XT BVBA)
MD5: 95cf4ce39cf5f59c4cb8612ad5678080 SHA-1: 39fa5b3c72f3b4b1f846e80ca57f906c790b1625 SHA-256: ec1844d4b1a0a93b97259c01e5404fad34326b742f52d3b5ecc637bb2d7a4550
62 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file exhibits multiple indicators of malicious intent, including embedded JavaScript streams and embedded script payloads. The presence of XFA forms and AcroForm buttons suggests an attempt to create an interactive lure. The embedded JavaScript, specifically javascript_obj0133_000.js and javascript_obj0134_001.js, is the primary mechanism for executing malicious code, likely downloading and executing a second-stage payload. The document body was not parsable, limiting further analysis of the lure.

Heuristics 8

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xfa/promoted-desc/

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0006.bin
51886c02f18523c864de9517a248d92d526ae6888aaed7586d0f989b0fa381e8
pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x4B03 163 bytes
embedded_file_obj0007.bin
267bc6bcdb8ed6e633f25fa68791bd9ceeb332247a849a3e3bfeee63b6d55c90
pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x4BF2 2405 bytes
embedded_file_obj0008.bin
08cae221857a208d72230ddb7c80fec725beeff56378b5f3454acfed9f8738b1
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x4FE4 2921 bytes
embedded_file_obj0009.bin
1715982188cf22e2877bd76c2a70243d16c113fc64cc0c8020610ce5644399c8
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x5388 1535 bytes
embedded_file_obj0010.bin
2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
pdf-embedded-file PDF EmbeddedFile object 10 at offset 0x5647 80 bytes
embedded_file_obj0011.bin
4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
pdf-embedded-file PDF EmbeddedFile object 11 at offset 0x56EF 56 bytes
javascript_obj0133_000.js
529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f
pdf-javascript-stream PDF /JS object 133 at offset 0x7139 1363 bytes
javascript_obj0134_001.js
e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a
pdf-javascript-stream PDF /JS object 134 at offset 0x7315 902 bytes
javascript_obj0135_002.js
0ab3d232b2f2272b7039ee3e45d0be78ade06bb45327a799559ad4a592ef5a3d
pdf-javascript-stream PDF /JS object 135 at offset 0x746E 1169 bytes
stream_001_off000001da.js
26218a59363e858154224edbe3b445f354c4f341aa36b2291598a74c6c570668
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1DA 68830 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 long base64-like blob(s).
stream_002_off000039b3.bin
96f3b95ac590a24927aef9abf434358866dbefb8e8fe69b77b4b3dbd0e90e048
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x39B3 856 bytes
font_00_sfnt_off00007f1e.bin
1626e6329f65d0d35cdf751ec668ac4b8800d726707d01e7810bb8297d789dee
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F1E 94351 bytes
font_01_cff_off00019727.bin
77a0b6c3eea44eabe1eca27c9a3556172dbbac4102a91eebaaca2ab4e62f2f25
pdf-font-stream PDF embedded font (cff) at offset 0x19727 5600 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.42, consistent with packed or encrypted content.
font_02_cff_off0001ad79.bin
19164b1e8011f1baf8fcc59c104786acda8c6d3aadd1a7e0607059d9baecca17
pdf-font-stream PDF embedded font (cff) at offset 0x1AD79 3195 bytes