LimeRAT — PDF malware analysis

Static analysis result for SHA-256 aa3ecd25cb55e093…

MALICIOUS

PDF

1.14 MB
MD5: 26bdcce2459cca07d46031fc8e55b41f SHA-1: 5809a126b44fe5046bbfbc44b1602a463eecf367 SHA-256: aa3ecd25cb55e093f8527fab340860976ce305a95e6224ae65293f0d2a003e78
142 Risk Score

Malware Insights

LimeRAT · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1105 Ingress Tool Transfer

The PDF contains an embedded Windows executable payload, identified by ClamAV as Win.Dropper.LimeRAT-9776087-0. The high stream count suggests obfuscation. The embedded executable is the primary indicator of malicious intent, likely serving as a dropper for the LimeRAT family.

Machine Learning

  • Nyx PDF Classifier clean score 0.0032

Heuristics 4

  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_024_off00114ce4.bin
7a88fcd386c99fa5fae8fc5b0d36e6ecc296d024fb219bc6f9358eddf25ebe60
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x114CE4 40480 bytes
embedded_pdf_0011f003.exe
3b7544b8b50b707d00cf332ae1fa6097ec61b06ad47bb4a0347498a67421e8c0
embedded-pe PDF decompressed stream PE payload at offset 0x11F003 21504 bytes
Detection
ClamAV: Win.Dropper.LimeRAT-9776087-0
Obfuscation or payload: unlikely
font_01_sfnt_off00118ea1.bin
0e6f7463466fed87efc13cdee4b86450c86aaaa4ad4b60be4fcb5ae94235c0da
pdf-font-stream PDF embedded font (sfnt) at offset 0x118EA1 36780 bytes