Malicious PDF — malware analysis report

Static analysis result for SHA-256 040dcaca724bb55d…

MALICIOUS

PDF

1.35 MB Created: 2026-04-30 02:31:36 -06:00 Authoring application: Microsoft® Word para Microsoft 365 First seen: 2026-05-18
MD5: 4ab350427eebd576f3f58d1bf05e0e93 SHA-1: 8206bdbe9c8a146508a57a9c5180dee0e902748c SHA-256: 040dcaca724bb55dd4bd604e50adf437a17d2d56454f7cbac0a41db39209f45e
758 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9604

Heuristics 17

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • TrueType bitmap font + active content — CVE-2023-26369 related high CVE related PDF_CVE_2023_26369_RELATED
    PDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
  • ClamAV: Pdf.Tool.Agent-1388586 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Tool.Agent-1388586
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\Practica II - Backdoors 2025-26.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
    An /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
  • Suspicious extracted artifact critical EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • /Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JS
    PDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://github.com/Veil-Framework/Veil In PDF document text
    • http://www.zeustech.net/Referenced by PDF JavaScript
    • http://]hostname[:port]/pathIn extracted file (Practica_II_-_Backdoors_2025-26.pdf)
    • tcp://172.20.10.5:4444In extracted file (Practica_II_-_Backdoors_2025-26.pdf)
    • https://wwww.microsoft.com0In extracted file (font_13_sfnt_off001456ec.bin)
    • https://www.welivesecurity.com/la-es/glosario/#BPDF link annotation
    • https://www.welivesecurity.com/la-es/2015/04/17/que-es-un-backdoor/In PDF document text
    • https://www.hybrid-analysis.com/In PDF document text
    • https://www.hybrid-analysis.com/=In PDF document text
    • http://www.virustotal.com/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://www.apache.org/Referenced by PDF JavaScript
    • http://www.microsoft.com/typography/ctfontshttp://www.fonts.comMicrosoftIn extracted file (stream_017_off000fba21.bin)
    • http://www.microsoft.com/typography/fonts/default.aspxIn extracted file (stream_017_off000fba21.bin)
    • http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn extracted file (font_01_sfnt_off0010977e.bin)
    • http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In extracted file (font_01_sfnt_off0010977e.bin)
    • http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn extracted file (font_01_sfnt_off0010977e.bin)
    • http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In extracted file (font_01_sfnt_off0010977e.bin)
    • http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn extracted file (font_01_sfnt_off0010977e.bin)
    • http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In extracted file (font_01_sfnt_off0010977e.bin)
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In extracted file (font_01_sfnt_off0010977e.bin)
    • http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In extracted file (font_01_sfnt_off0010977e.bin)
    • http://www.microsoft.com/pkiops/docs/primarycps.htm0@In extracted file (font_01_sfnt_off0010977e.bin)
    • http://www.microsoft.com/TypographyIn extracted file (font_01_sfnt_off0010977e.bin)
    • http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (font_02_sfnt_off00114baf.bin)
    • http://www.microsoft.com/typography/fonts/In extracted file (font_03_sfnt_off0011daa9.bin)
    • http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlMicrosoftIn extracted file (font_12_sfnt_off00143eb7.bin)
    • http://www.monotype.com/html/type/license.htmlIn extracted file (font_12_sfnt_off00143eb7.bin)
    • http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0ZIn extracted file (font_13_sfnt_off001456ec.bin)
    • http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0In extracted file (font_13_sfnt_off001456ec.bin)
    • http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0ZIn extracted file (font_13_sfnt_off001456ec.bin)
    • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0��In extracted file (font_13_sfnt_off001456ec.bin)
    • http://www.microsoft.com/PKI/docs/CPS/default.htm0@In extracted file (font_13_sfnt_off001456ec.bin)
    • http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0lIn extracted file (font_13_sfnt_off001456ec.bin)
    • http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0In extracted file (font_13_sfnt_off001456ec.bin)
    • http://www.microsoft.com/pkiops/Docs/Repository.htm0In extracted file (font_13_sfnt_off001456ec.bin)
    • http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0In extracted file (font_13_sfnt_off001456ec.bin)

Extracted artifacts 19

Files carved from inside the sample during analysis.

FilenameKindSourceSize
Practica_II_-_Backdoors_2025-26.pdf pdf-embedded-file PDF EmbeddedFile object 579 at offset 0x14E7D8 73802 bytes
SHA-256: 460c5d337a4b1f0260839702379f89c3de11269d0513c0916c0ed83e81e6a25e
Detection
ClamAV: Win.Trojan.Swrort-5710536-0
Obfuscation or payload: likely
actual_type=PE; declared_or_context_type=PDF; filename=Practica_II_-_Backdoors_2025-26.pdf; kind=pdf-embedded-file Static shellcode analysis recovered the Metasploit stager connect-back address: 172.20.10.5:4444 (reverse/x86, lab (non-routable)) Static shellcode analysis found candidate code region(s). Indicators: SC_PEB_ACCESS, SC_PUSH_STRING, SC_STR_GETPROCADDRESS Static shellcode analysis recovered API/import strings: kernel32.dll, advapi32.dll, KERNEL32.DLL, ADVAPI32.DLL, LoadLibraryA, GetProcAddress
javascript_obj0580_000.js pdf-javascript-stream PDF /JS object 580 at offset 0x159411 81 bytes
SHA-256: 4abba496471628fc382f6c2bc33ce23918cad32e600af4f38139581270da1597
Preview script
First 1,000 lines of the extracted script
this.exportDataObject({ cName: "Practica II -  Backdoors 2025-26", nLaunch: 0 });
stream_004_off00044c8c.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x44C8C 1157580 bytes
SHA-256: 80756d575439fa6a7d712f4911c6642b1040b27d0e614f02982027ce7dfa617a
stream_007_off0006b762.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6B762 587640 bytes
SHA-256: 1836d94d588c50142a1d8a531497e52261b9c5c3a426876367b59627aedee49c
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 88 long base64-like blob(s).
stream_008_off0007375c.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7375C 1040760 bytes
SHA-256: dae9cf1deb6672500252bbc0324ea5c3d80eaa2d1ced97d2b0ebbb8b39ae94c8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 115 long base64-like blob(s).
stream_017_off000fba21.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xFBA21 139704 bytes
SHA-256: 54d011b993998df79709400b1d83b69c9f3feb5939fc0fc48c321532c02f8495
font_01_sfnt_off0010977e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10977E 94704 bytes
SHA-256: 6cdb4a4bb394188035b7d99cd253c1d4751f81a0e39c089a6af621a05ef24cfa
font_02_sfnt_off00114baf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x114BAF 83332 bytes
SHA-256: cc9a2a3ae58105d2ca6d4776fcf80d184e8bb3a9bff4920c9a8291772f3cc01d
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: heap spray 0x41 (A)
font_03_sfnt_off0011daa9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11DAA9 18156 bytes
SHA-256: a4d43af5b13233130876a262974514a5c7e1aa8c73b0da8e118044cec1a21681
font_04_sfnt_off0011fce0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11FCE0 15512 bytes
SHA-256: 6e2b53e7bf43fca05ebfa4a704d2340e358ad88c5fd43122b6d2183379a3cbc8
font_05_sfnt_off0012174d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12174D 44496 bytes
SHA-256: 53e02943e48020c26ae9e6e2fa956795c71909ffde692e94f9ae20667646fc27
font_06_sfnt_off00125a50.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x125A50 50496 bytes
SHA-256: 70e385f41b176115237870a68c272dcf685595afa2a72efdf69a2ac9c36769cc
font_07_sfnt_off00127937.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x127937 51412 bytes
SHA-256: 80ba8a8bf77a4e2d2bc0f6ae812e7fb14604e8af32f643def31a326c4949814d
font_08_sfnt_off0012adf1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12ADF1 94508 bytes
SHA-256: 99aa06e528ea6046334b572c9a678cdb546d1e1f46a578b0d340e60c50093692
font_09_sfnt_off00135668.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x135668 51928 bytes
SHA-256: 649447603640a875407de2362fafebbda3a9d8ae1021cf1b6cf88cd796bb59c3
font_10_sfnt_off00138b1d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x138B1D 54848 bytes
SHA-256: 19736f5258f23b94706ccefbc91ea02e43c6d5b537cc17f777396d26f2d4f215
font_11_sfnt_off0013c34a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x13C34A 76704 bytes
SHA-256: 814bddbbdbf3824b8302f41151abed8d4a3e0fd9835ca88c9f1e226b2db2fe85
font_12_sfnt_off00143eb7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x143EB7 11088 bytes
SHA-256: 086b4c456dbe6f09f8c99517bcda6cd0f82646bc0cf77bf0a1e64dd9a7c38fd3
font_13_sfnt_off001456ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1456EC 46164 bytes
SHA-256: e37e30e211d74e3ae2594b69c9d243a147744dc4bc52848460549ca6d3f43e64