Malicious PDF — malware analysis report

Static analysis result for SHA-256 f01e56bf4fdeb799…

MALICIOUS

PDF

596.2 KB Created: 2010-03-22 12:14:01 -04:00 Authoring application: Adobe LiveCycle Designer ES 8.2
MD5: c66396e556731bc354f5bdec9bd94fe0 SHA-1: b95c1405d108fdc8c3e3e1802230c9772d7c889c SHA-256: f01e56bf4fdeb799f24fa4dff67a64b76593a0fb5a37e57f6231b5a535fa2577
94 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1059.001 PowerShell

The PDF contains embedded JavaScript and an embedded file, strongly suggesting it is designed to exploit vulnerabilities and download further malicious content. The ML classifier also flagged this PDF as malicious. The embedded file 'embedded_file_obj0249.bin' is likely the second-stage payload. No specific family could be identified.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6561

Heuristics 9

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xfa/promoted-desc/

Extracted artifacts 20

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0013.bin
707681ab686c938b2cfcc301c1476436d05eb4b637a0ceb3f84ce5a46a51ae40
pdf-embedded-file PDF EmbeddedFile object 13 at offset 0x68C 1909 bytes
embedded_file_obj0075.bin
4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
pdf-embedded-file PDF EmbeddedFile object 75 at offset 0x5183 56 bytes
embedded_file_obj0188.bin
f7ee3ef2f8f35d669a6c2b8b0b0ee89655bbc3d04b107a8d22531830f6fc28a1
pdf-embedded-file PDF EmbeddedFile object 188 at offset 0x2A9BD 86 bytes
embedded_file_obj0249.bin
07f6a17a65d691d693c17a8d8f022b21c9d1567b2e64a29155f3ba7cc4aecceb
pdf-embedded-file PDF EmbeddedFile object 249 at offset 0x3215D 289965 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 long base64-like blob(s).
embedded_file_obj0309.bin
ea932487190618598b516984a8a2f0ec8738d25384d26a49f55db2677e2df0be
pdf-embedded-file PDF EmbeddedFile object 309 at offset 0x40A04 1393 bytes
embedded_file_obj0370.bin
2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
pdf-embedded-file PDF EmbeddedFile object 370 at offset 0x458C5 80 bytes
embedded_file_obj0545.bin
bc3195a0f6975c7414a17957c94a56dc7646b92934b0478c8ac7a9ab4f406fd1
pdf-embedded-file PDF EmbeddedFile object 545 at offset 0x8964E 1616 bytes
embedded_file_obj0605.bin
2d58413fda1ff20c994606823bf49e41194612c0137b6315e50fa7bdc01f1e09
pdf-embedded-file PDF EmbeddedFile object 605 at offset 0x8F818 2423 bytes
javascript_obj0042_000.js
f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8
pdf-javascript-stream PDF /JS object 42 at offset 0x2C1A 1532 bytes
javascript_obj0103_001.js
826c5622c798d67e5281cca7e05933dddc90ccdcb0a6177c9f7d06f11bef8f7f
pdf-javascript-stream PDF /JS object 103 at offset 0x61CD 2795 bytes
javascript_obj0398_002.js
4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
pdf-javascript-stream PDF /JS object 398 at offset 0x46CBD 870 bytes
stream_024_off0000c072.bin
3849aaa28914e08e608524e4a3f1068792e87faf78ef933525771425768f0a82
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xC072 178848 bytes
stream_087_off00051a9c.bin
1e8564d3d89047875dccaa98279599de9d7ddf77240906041f1156ba8edf3315
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x51A9C 352198 bytes
stream_104_off0008baf8.bin
d5cb5eaa0ae2be42691a0b907f28365ec89e12abe112f088d959ce7bf58059e5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8BAF8 30572 bytes
objstm_0195_00.bin
7f6501e96871f789be3bb0ffe4a9d085f596427d6118b4ace57cd157bbe59d13
pdf-objstm-decoded PDF /ObjStm 195 0 obj (inflated) 29185 bytes
font_00_sfnt_off000071ef.bin
7c417a1930ba82db8ca23330edc1d88c3bef0aeaf548d0b5207c32d21fc45466
pdf-font-stream PDF embedded font (sfnt) at offset 0x71EF 26153 bytes
font_01_sfnt_off00024e98.bin
9c1736778d8905f958b5eb079ce943866407373d6f5eecd8e7b3d3dd5b4ad24d
pdf-font-stream PDF embedded font (sfnt) at offset 0x24E98 40786 bytes
font_02_sfnt_off0002e551.bin
37cf5ae2c58a58613ffb3685e18a1c0192f8075d1fa35c9697c1902f6bff6daf
pdf-font-stream PDF embedded font (sfnt) at offset 0x2E551 21079 bytes
font_03_sfnt_off0004b93b.bin
df57e7dbe4730a1cfc953898017fa7a296dd490ca6175444343e039e09a88c93
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B93B 30053 bytes
font_04_sfnt_off00084ddb.bin
d1565d3e4e0d88b58ed08357eac343c8004d1ba06c8eacf004ca1e972d58397d
pdf-font-stream PDF embedded font (sfnt) at offset 0x84DDB 24856 bytes