Donoff — PDF malware analysis

Static analysis result for SHA-256 d902bea19935f364…

MALICIOUS

PDF

57.5 KB Created: 2017-04-24 12:07:34 +03:00 Authoring application: iTextSharp’ 5.5.10 ©2000-2016 iText Group NV (AGPL-version)
MD5: 3cc39b9fe7dfdefcd9d4e8ed16a2c803 SHA-1: ec7d60f012656413314282508e02383560d312e7 SHA-256: d902bea19935f36483a7264e1d0571f198831da9acaded42d22318f360c39c63
174 Risk Score

Malware Insights

Donoff · confidence 95%

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The file is a PDF containing embedded JavaScript, identified by ClamAV as 'Doc.Downloader.Donoff-10030369-0'. The embedded JavaScript is likely responsible for downloading and executing a second-stage payload. The ML classifier also strongly indicates maliciousness. The specific family 'Donoff' is attributed based on the ClamAV detection name.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 5

  • ClamAV: Doc.Downloader.Donoff-10030369-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Downloader.Donoff-10030369-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
288699.docm
659b70509629e85235ba234c687534a7abea0fe2d1ed646c908d2d91d10c4e71
pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x61 70277 bytes
Detection
ClamAV: Doc.Downloader.Donoff-10030369-0
Obfuscation or payload: unlikely
javascript_obj0005_000.js
25b16c3e5fc42d2af761059c6585d8e2d6d6ea469e4a3c3caf9a454b1703bc7b
pdf-javascript-stream PDF /JS object 5 at offset 0xE034 446 bytes