Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd8ba88df50de86e…

MALICIOUS

PDF

10.4 KB
MD5: 72bdffbb723eb782da0a80754e7d0251 SHA-1: 020ea96cd11821969d3434d2d840c76598a08915 SHA-256: dd8ba88df50de86e7bb9b6343313e48e1e3b8d1a84ffca0a06a203a2f027cfdc
146 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF document contains embedded JavaScript and an embedded file named 'fra.doc'. The ClamAV detection 'Rtf.Downloader.CVE_2017-6336326-3' suggests that the embedded file is a downloader. The JavaScript action is configured to export the embedded data object, likely to trick the user into executing the embedded malicious file.

Heuristics 6

  • ClamAV: Rtf.Downloader.CVE_2017-6336326-3 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Rtf.Downloader.CVE_2017-6336326-3
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
fra.doc
b48926c91661bd0b42965abd7848e3635ced32b2d988f7bf614c608c60e99e16
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x3A1 39684 bytes
Detection
ClamAV: Rtf.Downloader.CVE_2017-6336326-3
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
javascript_obj0009_000.js
0d9cbfdc423c0f4bb3bb873ba8b564002b70426c2d531aae43379a91b64930ee
pdf-javascript-stream PDF /JS object 9 at offset 0x27D5 56 bytes
javascript_obj0009_001.js
a2c0520cc91242b6f04cec85851ab76799886833bf48dacb8d768408ff2168c5
pdf-javascript-stream PDF /JS object 9 at offset 0x27D5 54 bytes