Malicious PDF — malware analysis report

Static analysis result for SHA-256 ff3f3c714b7c2c0c…

MALICIOUS

PDF

8.7 KB
MD5: 29c56196e51b6137f6e9e8c819206bd7 SHA-1: ef9af584e0bc0d673546d385435b909689d25e34 SHA-256: ff3f3c714b7c2c0ceaf08fc1165179b7dd686806917611aff611ad9e065f82b2
110 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The critical CVE-2007-5659 heuristic indicates the PDF exploits a vulnerability via the Collab.collectEmailInfo method to execute JavaScript. Several JavaScript streams were extracted, with one being particularly large (16890 bytes), suggesting it contains the main payload. The ML classifier strongly flagged this PDF as malicious. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload, as is common with this type of exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659
    PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0001_000.js
5a52b0f76ff642e38aa380e1c58dca23b58884b5a21ce6f39ee29ab218750f4e
pdf-javascript-stream PDF /JS object 1 at offset 0xF 54 bytes
javascript_obj0013_001.js
71837dabf6a87c6da4271f41578b96cee4cf2e2514226c09cc3344ab2136afd0
pdf-javascript-stream PDF /JS object 13 at offset 0x383 16890 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 long base64-like blob(s).
legacy_pdfkit_stage_000.js
60203df0abbd12519b2eef567bd6beae66dee27b82be25cc48a70cbe657da489
deobfuscated-js reverse-string concatenation decoded JavaScript at offset 0x383 561 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
legacy_pdfkit_stage_001.js
4c4d5534b3e1c54c95f2d14aaf24c6100bea52a9ef73a7b2d915a04fa675a1d4
deobfuscated-js reverse-string concatenation decoded JavaScript at offset 0x383 566 bytes
legacy_pdfkit_stage_002.js
de9885a861cbf3096fb63ebdab5cb386461878e7f0a35572ef54b470dce86f2f
deobfuscated-js reverse-string concatenation decoded JavaScript at offset 0x383 565 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).
legacy_pdfkit_stage_003.js
7a1829a9e6de472d0d1a3e27337764d00c953467ef4a743a7fd1f4ebbb480bea
deobfuscated-js reverse-string concatenation decoded JavaScript at offset 0x383 351 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s).