Donoff — PDF malware analysis

Static analysis result for SHA-256 211c709301e4df02…

MALICIOUS

PDF

57.6 KB Created: 2017-04-24 12:07:35 +03:00 Authoring application: iTextSharp’ 5.5.10 ©2000-2016 iText Group NV (AGPL-version)
MD5: 50af30753b79fb456c9cf7333afc485f SHA-1: a1b88b47f17d17e5c28e93490ef53d977555656c SHA-256: 211c709301e4df0246c3fa82428583b9021d8324a6758f0df43122954e40e918
174 Risk Score

Malware Insights

Donoff · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF containing embedded JavaScript, flagged by multiple heuristics and ClamAV as 'Doc.Downloader.Donoff-10030369-0'. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload. The ML classifier also strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Doc.Downloader.Donoff-10030369-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Donoff-10030369-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
567646.docm
dce4dbd23fc432efc9cba4d90f91aaa566ad42baaaea189d71fdb7430d523609
pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x61 70330 bytes
Detection
ClamAV: Doc.Downloader.Donoff-10030369-0
Obfuscation or payload: unlikely
javascript_obj0005_000.js
e9d2f8dc166d2d0e3c0616377de2e511793a6a6b04e30fa08068ea71819178db
pdf-javascript-stream PDF /JS object 5 at offset 0xE068 446 bytes