MALICIOUS
130
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
The PDF contains a launch action that directly executes cmd.exe. This is a common technique for exploiting vulnerabilities in PDF readers to achieve arbitrary code execution. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 2
-
/Launch action target: "cmd.exe" critical PDF_LAUNCH_COMMANDPDF /Launch action specifies an executable target — references a known-dangerous executable (cmd, PowerShell, etc.).
-
Launch action high PDF_LAUNCHPDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
Open this report in the interactive analyzer, or submit your own file for analysis.