Malicious PDF — malware analysis report

Static analysis result for SHA-256 3eae0c41cf14f0e3…

MALICIOUS

PDF

423.1 KB Created: D072201508231444280530304700047 Authoring application: PyPDF2 First seen: 2022-06-20
MD5: 62e7e3f47f7290dd1f1ff7d5d520d7c7 SHA-1: bdabe9e6af7edc410a8c3dff47624875733f3111 SHA-256: 3eae0c41cf14f0e338bfb2cf47ca32e3a1c94d5daa5a22d9d72efa544b6ff664
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains an embedded SWF file named 'saddamfromiraq.swf', which is a strong indicator of malicious intent. The presence of RichMedia (Flash) heuristics further supports this. While the document body text is heavily corrupted and unreadable, the embedded artifact and associated heuristics suggest an attempt to execute code or exploit vulnerabilities, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier clean score 0.0909

Heuristics 4

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/photoshop/1.0/In PDF document text
    • http://ns.adobe.com/tiff/1.0/In PDF document text
    • http://ns.adobe.com/exif/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://www.gettyimages.comIn PDF document text

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
saddamfromiraq.swf pdf-embedded-file PDF EmbeddedFile object 80 at offset 0x456E8 59181 bytes
SHA-256: 827ca25aea201f2b8a1d13ea9f66a3c551f5ea4aa08a0ea4f642c4d6432bc6e9
Detection
ClamAV: No threats found
Obfuscation or payload: likely
actual_type=SWF; declared_or_context_type=PDF; filename=saddamfromiraq.swf; kind=pdf-embedded-file Carved artifact entropy is 7.97, consistent with packed or encrypted content.
stream_002_off00006009.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6009 13159 bytes
SHA-256: fa7cf5a5ef90e86221dbc186de7532b4d61a38169243041a86d1ba8806ee85fa
stream_004_off00007d7f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7D7F 20512 bytes
SHA-256: 5d0ce6dc77b8d223ca3633cdf18be0b16e3cea18ed62a54f75318bcdca681a60
stream_006_off0000ade9.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xADE9 28172 bytes
SHA-256: 56a2998b2efc9ba85f2c440c8a5809cfc115eed28a113f46162148c4c2fd66e0
stream_009_off0000f084.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF084 8055 bytes
SHA-256: 7111810a1825c248c72e44c7c5e3ccb74ac08ae0721e7d77f2aa4669a373284f
stream_011_off000106c4.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x106C4 12580 bytes
SHA-256: 468c55f50abd1a4e62edf52704e0c52a4e087ef4c72a78342abde552153e088e
font_05_sfnt_off00040f9a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x40F9A 25217 bytes
SHA-256: 72f5a4a1f561f172ccb026af6642f53f93bad38d7728d52bf4e62278effb7b8b
font_06_sfnt_off00063e2f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x63E2F 11314 bytes
SHA-256: ee3d00daed9b40692d8b50bdbbf9722be5bf885d2b0a51a681dc6c2294c701ac