Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed3c5bb26ed5c0d1…

MALICIOUS

PDF

1.32 MB Created: 2009-03-17 10:26:52 +08:00 Authoring application: Adobe Acrobat 8.1 Combine Files (via Adobe Acrobat 8.1)
MD5: 6ae6be0f852d3efe9ab5d736dfbb414c SHA-1: 9860c4f747540c4405f1766ec319be8d1d8967c4 SHA-256: ed3c5bb26ed5c0d158d3234490478251bae084ba380563c299561bdcc3578117
106 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file exhibits multiple suspicious findings, including embedded JavaScript and multiple embedded PDF files. One embedded PDF child was flagged with a high score due to multiple PDF_XREF_OFFSET_MISMATCH errors, indicating potential obfuscation or corruption. The presence of embedded files and JavaScript suggests an attempt to deliver a secondary payload or exploit vulnerabilities. The file is likely a dropper or exploit container.

Heuristics 7

  • Embedded PDF child has suspicious static findings critical PDF_EMBEDDED_CHILD_STATIC_TRIAGE
    PDF contains an embedded PDF stream whose extracted child matches suspicious or malicious PDF heuristics. Wrapper PDFs are commonly used to hide the actual exploit or lure payload from scanners that do not recursively inspect attachments.
  • PDF paints image(s) but contains no text operators medium PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 23

Files carved from inside the sample during analysis.

FilenameKindSourceSize
c993d.pdf
1da31f2da0eb50631fc41c9247c56a219656035be1ae869b1860ca2ec00db61d
pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x1F480 22610 bytes
d13744.pdf
ac5edbb87525d2f915fdc932a53ddd534e587789ae3fceec86f9c67a2ef3905d
pdf-embedded-file PDF EmbeddedFile object 12 at offset 0x29EBA 78126 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 15 long base64-like blob(s).
d13812.pdf
1e2de5e89a69da3eaae116c2a847ba3a3318c665753305af9e73ed4ee02722ce
pdf-embedded-file PDF EmbeddedFile object 13 at offset 0x2F109 77926 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 11 long base64-like blob(s).
d13915.pdf
d108f7d742191a37a6d1b13145b51f2258e088bc4f19cd2fae7cef937ccf253d
pdf-embedded-file PDF EmbeddedFile object 15 at offset 0x39A1F 43771 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 27 long base64-like blob(s).
d14402.pdf
a74179a36b051f1d73e70dc9f729ff0233ab464367c2912475030d20f56ac8ea
pdf-embedded-file PDF EmbeddedFile object 17 at offset 0x45BC3 25354 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 8 long base64-like blob(s).
c997c.pdf
52e1336eb9f8d976c45abaee8802ba5be233867120195d048ccaa1ce238f535f
pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x4C453 22420 bytes
d13220.pdf
173730b84ad71290f57c037f6ded3853c0444d6909ee06e103b66d53f6018386
pdf-embedded-file PDF EmbeddedFile object 11 at offset 0x51ADB 79469 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 60 long base64-like blob(s).
d13855.pdf
a40908cec89816d34cc72f7587717b0dae9426aa0a349246ec67f4778b5d8054
pdf-embedded-file PDF EmbeddedFile object 14 at offset 0x6149A 76766 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 34 long base64-like blob(s).
d14401.pdf
26d5ee1066fd08bbc4d81f556fd7cb495700cf57a93bdea9c329e449a35d555f
pdf-embedded-file PDF EmbeddedFile object 16 at offset 0x6C849 13364 bytes
d12271.pdf
23da8f446753bca4573fcb9360300be4b804d10e18d7ce4e2b1920b0d66b6d34
pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x79758 32482 bytes
d12391.pdf
278d6f8e8ef4569935c6836d176dfc3ca2b0867105df94fd4fcc4835ab18c2b5
pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x8095D 7619 bytes
d13203.pdf
1272b1af80709286f88b1dba3bda02de350a70501dfd11f7bfb6ef28e0fd7ffa
pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x8F303 6932 bytes
d13216.pdf
fd1070305b85bfb63c26c617752ce2e2bc783983166f3cebb71f35439c0d7ef5
pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x9C822 7987 bytes
d13217.pdf
853019c2989d61317dda3b1acca7390137a6b029f162bf20218d74c6755023ce
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xAB2BB 7855 bytes
d13218.pdf
7d81c311b546441e0bec7d78133351837d5fdb2996282db0e0c0b90f69c7ad78
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0xB989B 28113 bytes
d13219.pdf
73e7b6554975f1736c90bcc3d92d83e130dc5bfa639bba3664decd77c8d324c2
pdf-embedded-file PDF EmbeddedFile object 10 at offset 0xBF942 5424 bytes
d14403.pdf
58b9fcb5491623b1875ef973c7b95ef9e55c77c461ed761dbd87cf8d9cf648e7
pdf-embedded-file PDF EmbeddedFile object 18 at offset 0x11DCDF 6687 bytes
d14404.pdf
e020548763cd11c25e8e900e8cb31f93cea080b09aef03acc32d6ab673f18118
pdf-embedded-file PDF EmbeddedFile object 19 at offset 0x12A9FC 6228 bytes
d9414.pdf
ba61161bd4ed8f92bdcfe653f2ce400633ee2e566cb7dbbd938480407cdd2f62
pdf-embedded-file PDF EmbeddedFile object 20 at offset 0x1363C6 5589 bytes
d9843.pdf
49da57cb951758d5d17dbbf3eaa69bcb0eade03fc28ae59b7e9f5efefeed2ac4
pdf-embedded-file PDF EmbeddedFile object 21 at offset 0x140020 9097 bytes
javascript_obj0085_000.js
97e6c8fb70f6fedab160a41095c99dce3c9d53a0086d3a8d4e6d47cbe03dce61
pdf-javascript-stream PDF /JS object 85 at offset 0x61D 1946 bytes
stream_072_off0010df28.bin
97f94a1cb585b77a49387474256cef2e611ecdad0222229bb00ff94c060aa1b0
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x10DF28 9522 bytes
icc_00_off0001e6ef.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x1E6EF 3144 bytes