Malicious PDF — malware analysis report

Static analysis result for SHA-256 325fd50143d6d975…

MALICIOUS

PDF

9.4 KB
MD5: 5a7b67331ef7eeb591e13894889d3d64 SHA-1: 9ebc4e24fb0d4b6274878a9b7b25f2121f504fb8 SHA-256: 325fd50143d6d975d9db18cf9a069c9107c3bfcad5a07653d53c0fc315ee27ab
144 Risk Score

Malware Insights

MITRE ATT&CK
T1557 Adversary-in-the-Middle T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains embedded JavaScript and an embedded Microsoft Word document named 'Aguy1.doc'. ClamAV detections indicate this is a dropper for a malicious RTF file, likely exploiting CVE-2017-6336326. The embedded JavaScript is likely responsible for launching the embedded document, which in turn would execute the malicious payload.

Heuristics 5

  • ClamAV: Pdf.Dropper.Agent-7125210-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7125210-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
Aguy1.doc
d05b6f058b78e6802ba521564c71a375ad374ba9d7e2aa14c9864cd4dada5b4a
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x3A7 38350 bytes
Detection
ClamAV: Rtf.Downloader.CVE_2017-6336326-3
Obfuscation or payload: unlikely
javascript_obj0009_000.js
6e481d77ab477eae5c2502db5486eaaf6aa5a1888710c85c6dcad6af3a05e331
pdf-javascript-stream PDF /JS object 9 at offset 0x23D6 58 bytes
javascript_obj0009_001.js
5597ddb76444d26e5c2a0b19bd201ceac5582dc4ba55aa8a1d6930e97ead04ad
pdf-javascript-stream PDF /JS object 9 at offset 0x23D6 56 bytes