Analyzing Malicious PDF Files
Monday, December 22. 2008
Recently we added a new feature to cwsandbox.org: It is now also possible to upload suspicious PDF files that are then analyzed with the help of CWSandbox. Basically we open the submitted file with Acrobat Reader 8.1.1 since that version has several vulnerabilities. During runtime, we then observe the behavior of Acrobat and can detect suspicious changes such as new files on the hard disk or modified registry keys. Based on the generated report, it is then possible to detect malicious PDF files.
An example of such an analysis is available at https://cwsandbox.org/?page=details&id=520505&password=sfgpk. The PDF file
An example of such an analysis is available at https://cwsandbox.org/?page=details&id=520505&password=sfgpk. The PDF file
0416.pdf is malicious and has a rather good detection by AV vendors (21/38 - full details). In the CWSandbox report, we can see that the PDF file is opened with Acrobat Reader and then it drops a new file called wuweb.exe which is also executed. Afterwards, several other files are dropped and a server located in Singapore is contacted. Unfortunately this server is now offline, but presumably the server was used to download additional malware from the system



