Malicious PDF — malware analysis report

Static analysis result for SHA-256 01bc3eff064e338c…

MALICIOUS

PDF

55.1 KB Created: 2017-06-06 11:45:15 +03:00 Authoring application: iTextSharp’ 5.5.10 ©2000-2016 iText Group NV (AGPL-version)
MD5: e162a7704d47096b3e51eb9a7e19e98e SHA-1: 6321056c3b7125a0256fd03fc26a2c38e590f5f2 SHA-256: 01bc3eff064e338c98f0b2d14a636dc22e9ecc66b137c933ae9e5070ae2150de
176 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF contains embedded JavaScript that is designed to launch an embedded document named '789IVIIUXSF110.docm'. This embedded artifact was detected by ClamAV as 'Doc.Downloader.Jaff-6329914-0', indicating it likely functions as a downloader. The primary PDF itself was also flagged by ClamAV as 'Pdf.Dropper.Agent-7101783-0' and ML classifiers, confirming its malicious nature as a dropper for further malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 6

  • ClamAV: Pdf.Dropper.Agent-7101783-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7101783-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
789IVIIUXSF110.docm
199a51184aa2cf490314465f73e67049fb35df49c39ef3bef5965af7841c731e
pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x9E3 55000 bytes
Detection
ClamAV: Doc.Downloader.Jaff-6329914-0
Obfuscation or payload: unlikely
javascript_obj0004_001.js
548a0615ebce957f881b830276bc11c7613efb571c18dfb031f3cda62d35c86f
pdf-javascript-stream PDF /JS object 4 at offset 0xD69F 132 bytes