Malicious PDF — malware analysis report

Static analysis result for SHA-256 500f4bb016b36d45…

MALICIOUS

PDF

13.2 KB Authoring application: Python PDF Library 055 http072057057pybrary056net057pyPdf057
MD5: fb72e39620ae38a83efe7523e872696c SHA-1: 83faed2fa53e028d6e9731d14b9e37327e6c383e SHA-256: 500f4bb016b36d4554f917344cd02787f5f3c52a61b9e3b15398f8d14e88f8e5
94 Risk Score

Malware Insights

MITRE ATT&CK
T1559.002 Component Object Model Hijacking T1204.002 Malicious File

This PDF file was flagged as malicious by an ML classifier with high confidence. It contains embedded JavaScript and RichMedia (Flash) content, suggesting an attempt to exploit vulnerabilities. An embedded file named 'sploit.swf' was also extracted, which likely contains the exploit code. The benign URL found is not considered a primary indicator of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://adobe.com/AS3/2006/builtin

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
sploit.swf
70e6dbce3b11aaece2d38f1d315dee7736c7ab9138a74cdadc8126393c857018
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x107F 781 bytes