Malicious PDF — malware analysis report

Static analysis result for SHA-256 908c1d95505c4ea9…

MALICIOUS

PDF

894.8 KB
MD5: d293c5241681b1043ab14b6d8564f718 SHA-1: fd97889bd5c10f0f6244a7581cdb19252bcab4fd SHA-256: 908c1d95505c4ea9bcc21c6ba7c1a783f2d2bb19490350260ad84294645e0cf0
104 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains embedded Flash content (Tatsumaki.swf) and multiple JavaScript streams, strongly indicating a malicious intent. The ML classifier also flagged this PDF with high confidence. The presence of embedded JavaScript suggests an attempt to execute code, likely for exploitation or payload delivery. While specific URLs are benign, the embedded SWF and JavaScript are high-priority indicators.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 7

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdfx/1.3/
    • http://ns.adobe.com/xfa/promoted-desc/
    • http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
Tatsumaki.swf
93d4dfc19b02f2382f3de8207a9fea88c65503900c685c29eeed5c068b813d24
pdf-embedded-file PDF EmbeddedFile object 18 at offset 0x266C 4057 bytes
javascript_obj0006_000.js
56bd953c87a75007f2df1a16789df29bc537aa774f3a7886d20fa5a8189887cf
pdf-javascript-stream PDF /JS object 6 at offset 0xFC 8775 bytes
javascript_obj0006_001.js
175de8d8748df774ec99f36b72ddfe37c8af75c11f3c920febe86a195b79b0a1
pdf-javascript-stream PDF /JS object 6 at offset 0x119 524288 bytes