Malicious PDF — malware analysis report

Static analysis result for SHA-256 f49470461a07c65f…

MALICIOUS

PDF

43.2 KB
MD5: 4fcd6b5a2a03dbda8e33d2994d398935 SHA-1: aab64e724bfa313e99cc863a5176ca932f87ebff SHA-256: f49470461a07c65f98e1328b46d4831d5a6108f6b1735ca998da8b31859369ce
78 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.001 PowerShell

The sample is a PDF file that leverages the CVE-2009-4324 vulnerability, specifically targeting the media.newPlayer API. This vulnerability is used to trigger embedded JavaScript. The JavaScript code appears obfuscated but is designed to execute further malicious actions, likely downloading and executing a second-stage payload. The presence of deobfuscated JavaScript artifacts further supports this analysis.

Heuristics 4

  • media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324
    PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (identified after JavaScript deobfuscation)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0008_000.js
4d3797a7de4a014a3ff6a911384cf548e829e7b5581ea2f39135d45f2fd236f9
pdf-javascript-stream PDF /JS object 8 at offset 0x1E7 2221 bytes
legacy_pdfkit_stage_000.js
e25eb9dea927fc4a67324232040e7bccd1874be12a367fce24d0ca6ae7a3286e
deobfuscated-js repeated-marker hex decoded JavaScript at offset 0xAC8 2744 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
42025b552c7960b53abcd8cd732b01c8d109eccfdfefc352b9826c4d5807d414
deobfuscated-js cross-stage annotation API aliases at offset 0x1E7 81 bytes