Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae74de41a38c920a…

MALICIOUS

PDF

12.6 KB Created: 2018-09-04 09:44:29 +03:00 Authoring application: iTextSharp’ 5.5.10 ©2000-2016 iText Group NV (AGPL-version)
MD5: 29e101877070587ca4408d041d7bf72a SHA-1: cd8cf046c944b385f71762da612b8b839e1c7ace SHA-256: ae74de41a38c920a67861ac6d68ff73b4d459dcd1197f14a4f8e385495ce849e
256 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.001 PowerShell

The PDF contains embedded JavaScript and an embedded file named '04092018.pub', which was detected by ClamAV as 'Doc.Downloader.Olemal-6668035-0'. The embedded JavaScript likely facilitates the execution of the embedded file, acting as a downloader for a second-stage payload. The document body contains a standard confidentiality notice, but the embedded content is the primary indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 7

  • ClamAV: Doc.Downloader.Olemal-6668035-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Olemal-6668035-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
  • Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
04092018.pub
d65fedbeb78eb54ab688bc2ff9522008f584e8169043eaad51aa33c7bc09b8ff
pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x8B 48128 bytes
Detection
ClamAV: Doc.Downloader.Olemal-6668035-0
Obfuscation or payload: likely
Carved macro source contains an auto-exec entry point and execution/download terms.
javascript_obj0003_001.js
11555310b5b417a7a837ff8f276451781f83bab4e799d7f00ea402c16ce34771
pdf-javascript-stream PDF /JS object 3 at offset 0x2AE8 175 bytes