Malicious PDF — malware analysis report

Static analysis result for SHA-256 04f3ff5479d24c4d…

MALICIOUS

PDF

2.79 MB Created: 2010-03-05 15:48:57 -05:00 Authoring application: Microsoft PowerPoint (via Mac OS X 10.4.11 Quartz PDFContext) First seen: 2026-05-10
MD5: 12dab5da350ce226895b8c8486c5c1c7 SHA-1: 31fa947d7f27890c6644bb5c027bf791f69093ec SHA-256: 04f3ff5479d24c4d7490102f4b47dac39fd402e572ec848675e43a0208fdcba5
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The sample is a PDF containing embedded JavaScript, identified as a heap spray and download-and-execute behavior. A heuristic also indicates a password archive lure, suggesting the document is designed to prompt the user for credentials to decrypt a payload. The embedded URLs are benign, but the combination of JavaScript and the password lure points to a malicious document.

Machine Learning

  • Nyx PDF Classifier clean score 0.0002

Heuristics 5

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.cs.ucsb.edu/~seclab/projects/torpig/index.html In PDF document text
    • http://www.iec.chIn PDF document text

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_026_off002af603.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2AF603 39592 bytes
SHA-256: b06d2f02762eb36bde1104938fdfbbcfc48607180edfbefdccff009b9855a413
icc_00_off00000869.icc pdf-icc-profile PDF ICC profile at offset 0x869 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
icc_01_off0000132c.icc pdf-icc-profile PDF ICC profile at offset 0x132C 1328 bytes
SHA-256: eda03c8910c87b8a3e3c1ffbc35d223da8ae1d0dcfbad0c153c4eefbff436723
font_00_sfnt_off002ad0b8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2AD0B8 9968 bytes
SHA-256: cea9b128e59c0ccfe1c46069993f9f7c09ce4de231298b43fa85a20689f78ef2
font_01_sfnt_off002ae6cd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2AE6CD 4756 bytes
SHA-256: c5ee179b973116c57172c85e9ddaf146c15957799fb20a9b95e1bf5f833e2306
font_03_sfnt_off002b663a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B663A 6920 bytes
SHA-256: 164df63478dd466fdaa3ec1cbd1b41967289b3835172c4b05183b98c433f2681
font_04_sfnt_off002b7a05.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B7A05 4992 bytes
SHA-256: baf791bd3d09a329c64c151b23dbaf3379bcbb417d042c7b440d019f67bee993
font_05_sfnt_off002b87bb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B87BB 15752 bytes
SHA-256: aaaa8d0906ea488b3165bda581f21d93bcfd8b5e173f46c8e2cd4437b38f752d
font_06_sfnt_off002bb7f4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2BB7F4 20524 bytes
SHA-256: bd76648c95acfe686e8f935b99afcf23c77c84e6f3e51b38bfccfaa7cdd48cfd
font_07_sfnt_off002bf46c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2BF46C 4004 bytes
SHA-256: 1864ca6bb718fefeb85bb8f2ce83ca836e61521fd44890b45da57e9b15241a99
font_08_sfnt_off002c01d2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2C01D2 12672 bytes
SHA-256: 1ea74c69bddaa5815b875e1d51e5bb70e6785f201bef080677e6266f174e618f
font_09_sfnt_off002c2a02.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2C2A02 40580 bytes
SHA-256: a00d5643c45a375d6898c6117421801e1cb32f14f9a64ffa9ebbe641afc8fcb9