Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd5308043689e85c…

MALICIOUS

PDF

23.8 KB
MD5: b0a459947f236bb83bc1ea9f01d36599 SHA-1: e8ad2a258c7b2b99abfa5c8df03009ef9e5172ec SHA-256: fd5308043689e85c9d174822ff2fc06734a8ed75c50c902cfd8864d19fd6cebc
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.001 Malicious Link

The PDF file contains obfuscated JavaScript that leverages the CVE-2008-2992 vulnerability, specifically using the util.printf sink. The JavaScript is designed to be executed within Adobe Reader, indicating an attempt to exploit a known PDF reader flaw. The primary goal appears to be the execution of a secondary payload, as suggested by the heuristic firings and the nature of the exploit. No specific family could be identified due to the generic nature of the exploit.

Heuristics 5

  • util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992
    PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure. (identified after JavaScript deobfuscation)
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj111711_000.js
4daa818b151c83d394b20bbc01fd35fe056c45c12650059e7a0ed4dd2fbc7f64
pdf-javascript-stream PDF /JS object 111711 at offset 0x18E 3999 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
javascript_obj111712_001.js
7d9b673f092dea71faf9e220e643850d0b5df628ffbc3ca9b16451f1365a7d75
pdf-javascript-stream PDF /JS object 111712 at offset 0x1163 15145 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 4 long base64-like blob(s).
javascript_obj111713_002.js
298aa9d46d962527a0d09aaefd1c750e9d1cf6518876803e38a24b021604c411
pdf-javascript-stream PDF /JS object 111713 at offset 0x4CC2 4625 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
legacy_pdfkit_stage_000.js
2ce519949289064cac4d9ec5e2f03616b7ef69d371aebd8dd98fe04454eb0f63
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x1163 1413 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
e282e90aa5eca950df2ca38b720cea9e6025f175e744e4f996f2c8820ba8b08c
deobfuscated-js multi-marker percent-array decoded JavaScript at offset 0x4CC2 385 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
legacy_pdfkit_stage_002.js
10f9af31fd92b3b91a9b4519319d79eb5930aa1bb010269b5e328b0105274f48
deobfuscated-js multi-marker percent-array combined decoded JavaScript at offset 0x1163 1799 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).