Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9c5bc1428790077…

MALICIOUS

PDF

107.6 KB Created: 2018-06-12 09:41:10 -04:00
MD5: 83d7a5eb678e04815ffe219a2ecb355b SHA-1: 6c2b2206fb64b8387f5ad23487af42169261ae84 SHA-256: f9c5bc14287900771ad9c5375469d33ef7b67c80884910bdd8b612e80115f611
160 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9477

Heuristics 8

  • PDF auto-runs JavaScript form submission on open critical PDF_OPENACTION_JS_SUBMITFORM
    PDF uses /OpenAction to run JavaScript that calls submitForm() with an external HTTP(S) URL. Opening the document triggers the outbound submission path without requiring a normal link click.
  • PDF JavaScript shows fake Acrobat updater prompt high PDF_FAKE_ACROBAT_UPDATE_LURE
    PDF JavaScript displays Acrobat/update-themed language such as a document rendering engine update or remote connection to Adobe servers. When paired with JavaScript or external submission, this is a social-engineering lure rather than benign document text.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://please.do.not.click.on.this.link.instantrevert.net/XUjFvd1EzaDFWVEpvVUZwUVltbGlURW94VlhCMVQydHJibVZxTVdWRFIyY3daME0xTWt0TmVVNDFlR2x3Um1KM1VVczNORlpDTWxOb1pGUXpOVE00WkRndmFqaDJVVEJrYlV4U00wUkdabXR5Ym1nM1dEbFRSWEJSTTJOS1JEUldTek0zU1ZOSU4yWXpZMmM5TFMxd1FubFJlRE53YzNSdFJXWklUV3RXYWtwdFJtSm5QVDA9LS1hMTQ3MDdjOTY1M2ZjZDZmODU3MzA5NDc1MGYwNzU1OWQwOTMwNDk4?cid=73120517#FDF
    • https://please.do.not.click.on.this.link.instantrevert.net/XWmsxWVlXNTNNMHhuVXpkSFVEQndVbEI2TDA5Qk0wZ3dhVmREVjJKbk5UTnpTMkp4Y2xjNFRtZEJjM1pvVDNOelVEZHZkbVl2VkVneFNVTTNZbUUwWkVSNmQxbFZZMDlYWW05NFUyNVFVMkYzWTAxWk4zcEtSMHBuV0dsR1NEZERObk5pU1RONVEwdFBRMVowZWxCWVpYVjBSMFY0UlZkUlFrVkVjVEJuTUVWVldIWmxSelZDWm1zMk4xUldZek52U2pFeWMyVmpXak5QYkU1U2VHbG5kMVpGVDNrd1VUQkRia00zVW5saGVHNUVhbTQ1WlU5cFZIUlhXRzg1Umk5RkxTMVRVbEpXTmtzMVVsaFJSRGROU0ZSaFRWUlVRa05uUFQwPS0tNjAyYTMyMDkwODhjNzdiMTIxNDNhMjZkOTRiOGIwNGRhZmZlOTM2MA==?cid=73120517
    • https://please.do.not.click.on.this.link.instantrevert.net/XYTAwdksyVkxabkJvU0ZaNUsyVTJPVXhuV21ObFpIaEZkM1JuVTAxNGVtUlpRa1UyZGpWdFV6UnhiMlZqYzBrMVRTOW1hMmgzV1c1M1VWVkplakpYVVVKUVVrUmlVSGR0V0V4UVRYVlNNMVJpVmtWT1JVbGpSWFpaWW0xcmVXeG1VbnB6ZDAwNVIyeFlWVWQ2TUZWcFpGUmtNemhFUTFwRGNFUm9abVZtUm14eGMzWmlORFZEWVdremRuVjFWemd6VFZRMEwwWXZSMDAzV21sa1VXOVllbTEyVkhKbFdIRkdUMUpzVmpobk5HOUlkbGsxYVZscWRrUXJUR1pPU3pSdUxTMUliV05SY2xGaFdTOVpSVTFaTjI4emNGbEJkekpCUFQwPS0tOTQ4MDRhNzAzZjk4Y2QyYWY1NThlNmE0MGJkMjI1NTVmZTAxNTFjYg==?cid=73120517
    • https://please.do.not.click.on.this.link.instantrevert.net/XZFdadU5WQnpVRkpSYjNwaGVYaG1SMVp2TTJRMlUzcDJlRFExVUVGdk1IUnNiVFp6TVhCWVFrMHhObmh5U0hJeVNTdExjMUk0WW1jd2F6VllORkJrVlcxSk1tVlFNRmx4UkRGcWVqQlFZbTR3THpoSE1YSjBNRVJGUjBvNVNYQXpSSGhuWTFnMU5VZE1Ra1ZJY2paMlVXNHJNM0ZMVVcxT1VEUnBUak5wVldaV0swNWpWREU0VkUxYVJIRndSRTlsYkVzMWRrOVhVM3BrZUVwMU9YTkpVblF5YjFCaE0zbFNXbko0ZUZoTVpXTnRjSEJrZVhwb2F6UjJPRE5YTkhCd0xTMXZWeXN6UlROblVUVjJVbkpqZFRCNGNtbHlRM2gzUFQwPS0tZjBlYjEwMDZmNGM4NTNiYTA2MDU1OGZiMGVlNzVmODI1M2Q2MzRhZQ==?cid=73120517
    • https://please.do.not.click.on.this.link.instantrevert.net/XWmsxWVlXNTNNMHhuVXpkSFVEQndVbEI2TDA5Qk0wZ3dhVmREVjJKbk5UTnpTMkp4Y2xjNFRtZEJjM1pvVDNOelVEZHZkbVl2VkVneFNVTTNZbUUwWkVSNmQxbFZZMDlYWW05NFUyNVFVMkYzWTAxWk4zcEtSMHBuV0dsR1NEZERObk5pU1RONVEwdFBRMVowZWxCWVpYVjBSMFY0UlZkUlFrVkVjVEJuTUVWVldIWmxSelZDWm1zMk4xUldZek52U2pFeWMyVmpXak5QYkU1U2VHbG5kMVpGVDNrd1VUQkRia00zVW5saGVHNUVhbTQ1WlU5cFZIUlhXRzg1Umk5RkxTMVRVbEpXTmtzMVVsaFJSRGROU0ZSaFRWUlVRa05uUFQwPS0tNjAyYTMyMDkwODhjNzdiMTIxNDNhMjZkOTRiOGIwNGRhZmZl
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/tiff/1.0/
    • http://ns.adobe.com/exif/1.0/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0012_000.js
dcf816f68e74d02ba31dc3ac4c3dd02750c620bd793c6f8ff1ca3680d1943b6b
pdf-javascript-stream PDF /JS object 12 at offset 0x180A 627 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
javascript_obj0012_001.js
8129191080e6809b46c9007e444f7ab507aa5e5f72f308e5952e1029242daba5
pdf-javascript-stream PDF /JS object 12 at offset 0x1831 103950 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 8 long base64-like blob(s).
font_00_cff_off00019733.bin
9340d372ad75a105fdb1627a30e96f892e0dc7d9588c0150cf06b4fa72281cc0
pdf-font-stream PDF embedded font (cff) at offset 0x19733 4575 bytes