Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe1371f169e74495…

MALICIOUS

PDF

2.7 KB
MD5: 4854d7825128703785c8fd2bfe2595f3 SHA-1: 935ae0365f369fd2d2233acb4480a970a935d31a SHA-256: fe1371f169e74495abd75f453f8fd3dc5285bfefb7737b594a74771e281aaa5e
72 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious Attachment

The PDF file contains embedded JavaScript and RichMedia (Flash) content, indicating an attempt to exploit vulnerabilities. The presence of 'test.swf' in the document body suggests the embedded content is likely a Flash file intended to trigger an exploit. The embedded URLs, while not directly malicious, are associated with the XFA form technology used in the PDF, which can be a vector for exploits. The primary attack vector appears to be leveraging a Flash vulnerability within the PDF.

Heuristics 6

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0006_000.js
7b3775b68b186ae716c28e3a0e9c7a49d9807d2b473cf0042b476679c982402e
pdf-javascript-stream PDF /JS object 6 at offset 0x106 1561 bytes