Malicious PDF — malware analysis report

Static analysis result for SHA-256 246a524b7f179a86…

MALICIOUS

PDF

6.7 KB Authoring application: Python PDF Library 055 http072057057pybrary056net057pyPdf057 First seen: 2026-05-10
MD5: 7279a04d9e6ae472035534ace05644ae SHA-1: 3f39e8a208efa06e9160ab4c2b72c5dc0cea9fcc SHA-256: 246a524b7f179a862acde70edee5e7fb3f4c31ccdfccbb0e8f3e3f41691a4e48
168 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF document contains an embedded SWF file that triggers a known Flash Player vulnerability (CVE-2009-1862). This vulnerability allows for arbitrary code execution, likely to download and run a second-stage payload. The presence of the SWF file and the specific CVE firing strongly indicate a malicious exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 6

  • Adobe Flash/authplay SWF exploit in PDF — CVE-2009-1862 critical CVE likely CVE_2009_1862_FLASH_RICHMEDIA
    PDF combines RichMedia Flash activation with an embedded crafted SWF carrying Run_Sploit/HeapSpray/ByteArray markers. This is the static delivery shape associated with the July 2009 authplay.dll Flash-in-PDF vulnerability CVE-2009-1862.
  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://adobe.com/AS3/2006/builtin In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
sploit.swf pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x114C 781 bytes
SHA-256: 70e6dbce3b11aaece2d38f1d315dee7736c7ab9138a74cdadc8126393c857018
Detection
ClamAV: No threats found
Obfuscation or payload: likely
actual_type=SWF; declared_or_context_type=PDF; filename=sploit.swf; kind=pdf-embedded-file