Malicious PDF — malware analysis report

Static analysis result for SHA-256 5e490bf1018001d7…

MALICIOUS

PDF

13.7 KB
MD5: e1c2c8fcaec72b66d9a0ebeccdfe0ac6 SHA-1: 3dd4d37a712ddf2267f9afdf279fdc3b5195b3cf SHA-256: 5e490bf1018001d78c571c5520a16f7b5f56ecb7769a6cdb18866c58ece3721e
88 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file was flagged as malicious by an ML classifier and contains embedded Flash content (5.swf). This suggests an attempt to exploit vulnerabilities within the PDF reader or the Flash player to execute arbitrary code. The presence of XFA forms and embedded files further supports the likelihood of a malicious payload being delivered.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9732

Heuristics 4

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.1/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
5.swf
797559d3f1e4f62f7d7ec5a729b60c863e13118d22afb32eab08faf38dc7c87f
pdf-embedded-file PDF EmbeddedFile object 55 at offset 0x2A6C 2809 bytes
stream_000_off00000068.bin
69e17a0038b9273e6d005ef52313a832cb41b9cf9713d6134d0cf9f2e59298a7
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x68 434 bytes