Win.Worm.Mantan-1 — PDF malware analysis

Static analysis result for SHA-256 153d6bd2a1218875…

MALICIOUS

PDF

1.95 MB Created: 2003-07-07 09:34:42 Authoring application: Bando AUC 56.doc - Microsoft Word (via Acrobat PDFWriter 4.0 per Windows NT)
MD5: 6b7c685e00ff5a5b9e1d44355a49820b SHA-1: 2dbe4568f50748ae473044ee528075309a305cb9 SHA-256: 153d6bd2a121887595a39bff2e13154158fab8e890c433c7a7aa662169105258
366 Risk Score

Malware Insights

Win.Worm.Mantan-1 · confidence 95%

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The sample is a malicious PDF that leverages embedded JavaScript, indicated by PDF_JAVASCRIPT and PDF_EMBEDDED_SCRIPT_PAYLOAD heuristics. The JavaScript contains eval() calls and uses String.fromCharCode, suggesting obfuscation and exploit activity. The ClamAV detection of Win.Worm.Mantan-1 further confirms its malicious nature. The embedded script likely acts as a downloader for a secondary payload.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4690

Heuristics 11

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • ClamAV: Win.Worm.Mantan-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Worm.Mantan-1
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution
  • Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • String.fromCharCode low PDF_FROMCHARCODE
    String.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules.
  • ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85
    ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://linkshare.clarence.com/add.php?own=16
    • http://www.clarence.com/linkshare/images/linkshare.gif
    • http://ads.dada.it/adclick/CID=000028d96c11eee700000000/SITE=CLARENCE/AREA=CULTURA/AAMSZ=1X1/ACC_RANDOM=1070113316590/PAGEID=995000
    • http://linkshare.clarence.com/go.php?adm=0&id=243&ids=16
    • http://ads.dada.it/adclick/CID=00001ed4912d708d00000000/SITE=CLARENCE/AREA=CALENDARIO/AAMSZ=150X150/ACC_RANDOM=1069087938670/PAGEID=213033
    • http://ads.dada.it/adclick/CID=00002a69912d708d00000000/SITE=CLARENCE/AREA=CALENDARIO/AAMSZ=120X240/ACC_RANDOM=1069087938950/PAGEID=213033
    • http://ads.dada.it/adclick/CID=000028d86c11eee700000000/SITE=CLARENCE/AREA=CULTURA/AAMSZ=1X1/ACC_RANDOM=1069087939280/PAGEID=213033
    • http://www.icra.org/ratingsv02.html
    • http://www.clarence.com/calendario2004/
    • http://www.rsac.org/ratingsv01.html
    • http://www.clarence.com/
    • http://www.clarence.com/freeinternet/
    • http://chat.clarence.com/
    • http://forum.clarence.com
    • http://www.clarence.com/oroscopo/
    • http://www.clarence.com/cartoline/index.php
    • http://www.clarence.com/calendario2004/index.php
    • http://www.clarence.com/city/tobestrip/
    • http://sms.clarence.com
    • http://search.clarence.com
    • http://www.clarence.com/qpid/
    • http://webmail.clarence.com/
    • http://giochi.clarence.com/
    • http://search.clarence.com/links/
    • http://www.clarence.com/meteo/
    • http://blog.clarence.com/
    • http://www.clarence.com/cgi-bin/redir.cgi?http://big.clarence.com/
    • http://ads.dada.it/jserver/SITE=
    • http://ads.dada.it/adclick/SITE=
    • http://ads.dada.it/nserver/SITE=
    • http://www.dada.net
    • http://bacionimegan.clarence.com
    • http://forum.clarence.com/forumdisplay.php?s=&forumid=160
    • http://www.clarence.com/images/symbols/arrow.gif
    • http://www.clarence.com/misc/incontri-supereva/
    • http://www.clarence.com/city/tobestrip/images/stripcard_invio.gif
    • http://webmail.clarence.com
    • http://www.clarence.com/images/smallicons/novita/icocards.gif
    • http://blog.clarence.com
    • http://www.clarence.com/images/smallicons/novita/icoblog.gif
    • http://www.clarence.com/images/tmp/ico03.gif
    • http://www.clarence.com/contents/cultura-spettacolo/speciali/calendari2003/
    • http://www.clarence.com/contents/societa/memoria/
    • http://www.clarence.com/contents/societa/cowjones/
    • http://www.clarence.com/contents/partire/webcam/
    • http://www.clarence.com/contents/societa/wwwar/
    • http://www.clarence.com/contents/cultura-spettacolo/cinema/recensioni/
    • http://linkshare.clarence.com
    • http://www.clarence.com/linkshare/scripthp.php?id=16
    • http://www.clarence.com/calendario2004/pics/img3f4865a43cb8c.jpg
    +60 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0002649b.bin
1afbf06715f69b90b6215e0696d6a5a5f7bc0f388ed08f731077aa73d90fb52e
pdf-embedded-script PDF decompressed stream script payload at offset 0x2649B 2047852 bytes
Detection
ClamAV: Win.Worm.Mantan-1
Obfuscation or payload: likely
Carved artifact contains 20 shell/COM execution token(s). Carved artifact contains 6 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
font_00_sfnt_off00010493.bin
4958e4127f8f663249329b037bcce131dc34b24048f789075c4cc54e9efa4551
pdf-font-stream PDF embedded font (sfnt) at offset 0x10493 15388 bytes