Attackers can create files with a PDF signature by manipulating the file structure to bypass AVs. An MHT file created in Word and containing macros is embedded in a PDF file. Then, when this file is recognized as a PDF, the embedded Word file in the PDF is opened.
When we open the malware, the Word application opens as follows.
data:image/s3,"s3://crabby-images/688da/688da920b9a280152cb030da672b436754bfbd67" alt=""
When we look at the header information of this file, we see a PDF signature.
data:image/s3,"s3://crabby-images/55f77/55f77fd138d3a9840164aefbde507c80b2c61729" alt=""
And when we open the file with the hex editor, the first bytes start with the PDF signature and then continue with other objects. It looks like a normal PDF file until here.
data:image/s3,"s3://crabby-images/cef2f/cef2f7610c54b9c8c8488a0d8d669d8e1f49fe1a" alt=""
But if we analyze a little more, we can view the MHT file in other objects of the file as follows:
data:image/s3,"s3://crabby-images/90b0e/90b0e151230ed046ea79ff43de306e2b73f78aad" alt=""
The malicious VBA codes inside the MHT start communicating with the C2 server.
data:image/s3,"s3://crabby-images/3b6f6/3b6f6368e6f9098ff35c6f10d7ca4991ef4eea81" alt=""
Docguard Catches Every Malware!
This malware bypassed all antiviruses, but DOCGuard can detect it in seconds!
data:image/s3,"s3://crabby-images/7bd5a/7bd5a8808534528950f3adba5ea2c64db13687bf" alt=""
data:image/s3,"s3://crabby-images/3d6cf/3d6cf36375185b64c0bb8738f15c09e236b0145d" alt=""
IOCs
SHA256 | 5b677d297fb862c2d223973697479ee53a91d03073b14556f421b3d74f136b9d |
SHA256 | 098796e1b82c199ad226bff056b6310262b132f6d06930d3c254c57bdf548187 |
SHA256 | ef59d7038cfd565fd65bae12588810d5361df938244ebad33b71882dcf683058 |
C2 Server | https[:]//web365metrics.com |
C2 Server | https[:]//cloudmetricsapp.com |