Malicious PDF — malware analysis report

Static analysis result for SHA-256 930f07266f92d268…

MALICIOUS

PDF

416.2 KB Created: D072201508231444280530304700047 Authoring application: PyPDF2 First seen: 2022-06-20
MD5: 6c02922bd1debdfac3c3fde913f060db SHA-1: 6d239af487442a8ceb6f53977703ee2e0e9f289e SHA-256: 930f07266f92d26833ba2081f05a49388920d1ee5c2a584a5227a7f694bc8d2d
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains an embedded SWF file named 'saddamfromiraq.swf', which is a strong indicator of malicious intent. The presence of RichMedia (Flash) heuristics further supports this. While the document body text is heavily corrupted and unreadable, the embedded artifact and associated heuristics suggest an attempt to execute code or exploit vulnerabilities, likely delivered as a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier clean score 0.0909

Heuristics 4

  • RichMedia (Flash) high PDF_RICHMEDIA
    PDF contains /RichMedia (Adobe Flash) which is a historic exploit vector
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/photoshop/1.0/In PDF document text
    • http://ns.adobe.com/tiff/1.0/In PDF document text
    • http://ns.adobe.com/exif/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://www.gettyimages.comIn PDF document text

Extracted artifacts 8

Files carved from inside the sample during analysis.

FilenameKindSourceSize
saddamfromiraq.swf pdf-embedded-file PDF EmbeddedFile object 80 at offset 0x456E8 52095 bytes
SHA-256: 66f0e4c2e033ee349112246d6c62d5d8a5fab6601b9a716518ea436731848c76
Detection
ClamAV: No threats found
Obfuscation or payload: likely
actual_type=SWF; declared_or_context_type=PDF; filename=saddamfromiraq.swf; kind=pdf-embedded-file Carved artifact entropy is 7.97, consistent with packed or encrypted content.
stream_002_off00006009.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6009 13159 bytes
SHA-256: fa7cf5a5ef90e86221dbc186de7532b4d61a38169243041a86d1ba8806ee85fa
stream_004_off00007d7f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7D7F 20512 bytes
SHA-256: 5d0ce6dc77b8d223ca3633cdf18be0b16e3cea18ed62a54f75318bcdca681a60
stream_006_off0000ade9.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xADE9 28172 bytes
SHA-256: 56a2998b2efc9ba85f2c440c8a5809cfc115eed28a113f46162148c4c2fd66e0
stream_009_off0000f084.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF084 8055 bytes
SHA-256: 7111810a1825c248c72e44c7c5e3ccb74ac08ae0721e7d77f2aa4669a373284f
stream_011_off000106c4.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x106C4 12580 bytes
SHA-256: 468c55f50abd1a4e62edf52704e0c52a4e087ef4c72a78342abde552153e088e
font_05_sfnt_off00040f9a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x40F9A 25217 bytes
SHA-256: 72f5a4a1f561f172ccb026af6642f53f93bad38d7728d52bf4e62278effb7b8b
font_06_sfnt_off00062281.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x62281 11314 bytes
SHA-256: ee3d00daed9b40692d8b50bdbbf9722be5bf885d2b0a51a681dc6c2294c701ac