logo

MalDoc in PDF - Detection bypass by embedding a malicious Word file into a PDF file –

ID: a657542d-5f3a-5d2f-a036-9bd7db16a62c

STIX ID: report--a657542d-5f3a-5d2f-a036-9bd7db16a62c

Feed Name: JPCERT Blog

Threat Score
65/100

Date Published: 2023-08-28

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

JPCERT/CC details a new technique, "MalDoc in PDF", where an attacker appends a Word MHT file containing VBA macros to a PDF file so it retains PDF headers yet opens in Microsoft Word and can execute macros; this enables evasion of PDF-focused scanners and some automated analysis. The advisory includes example YARA detection, recommends using olevba to extract and analyze embedded macros, and publishes C2 domains and three malware hashes observed in the July incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.