Malicious PDF — malware analysis report

Static analysis result for SHA-256 0bf77f8420aca050…

MALICIOUS

PDF

747.0 KB Authoring application: Viraciregavi First seen: 2026-05-03
MD5: c1d602f423d4c7bbd757edc4f97ce180 SHA-1: eba6d6fc194527b46a49a761ebe7624c19b95686 SHA-256: 0bf77f8420aca0505f84877fce964a2a4facd5675858d5a6bb83146e9646c5b3
170 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The critical heuristic firing for CVE-2010-1297 indicates a heap spray vulnerability exploitation. This is further supported by the PDF JavaScript and embedded JS stream findings, suggesting the execution of malicious code. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to download and execute a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9745

Heuristics 6

  • CVE-2010-1297 — Adobe Flash/Reader authplay heap-spray (Flash-in-PDF) critical CVE likely CVE_2010_1297
    PDF embeds a Flash (SWF) object via RichMedia and its JavaScript heap-sprays to groom memory for the embedded Flash exploit. This is the CVE-2010-1297 (authplay.dll) Flash-in-PDF memory-corruption shape; the spray is recovered after de-obfuscating space-padded %u, fromCharCode and \u builders that evade the raw heap-spray rules.
  • ClamAV: Pdf.Tool.HeapSprayHeuristic-6301967-1 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Tool.HeapSprayHeuristic-6301967-1
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/t/pg/In PDF document text
    • http://ns.adobe.com/xap/1.0/g/img/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xmp/InDesign/privateIn PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://www.iec.chIn PDF document text

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
icc_00_off0001ef9a.icc pdf-icc-profile PDF ICC profile at offset 0x1EF9A 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
font_00_cff_off000002ef.bin pdf-font-stream PDF embedded font (cff) at offset 0x2EF 499 bytes
SHA-256: 2789af23995f8af33b2dae091e9b962494e0b8b0e898fada623820ee9686b3ca
font_01_sfnt_off00004666.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4666 48764 bytes
SHA-256: 336a7a084a76c025a84d5a8cbd6080db9a267cde0e24fe672acabed56b19aa8d
font_02_cff_off00017d4f.bin pdf-font-stream PDF embedded font (cff) at offset 0x17D4F 1390 bytes
SHA-256: b7acc2e77938f52ea0e0e99ad276600cacf4c9a68f9966b0cff658984fc5fdfe
font_03_cff_off00018686.bin pdf-font-stream PDF embedded font (cff) at offset 0x18686 5979 bytes
SHA-256: 650743b0083f4117eafe6d934f210cd07b94d118b25ed99f041916d1b6f42ac7
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.40, consistent with packed or encrypted content.
font_04_cff_off0001a110.bin pdf-font-stream PDF embedded font (cff) at offset 0x1A110 6612 bytes
SHA-256: cf4944c56c01f4a65c36b5010c12128ca3ddbe0e6806e8b147a7b04453bfa751
font_05_cff_off0001bc24.bin pdf-font-stream PDF embedded font (cff) at offset 0x1BC24 3369 bytes
SHA-256: eb7fc9a0f6b5c973d758c18668889ef5241421e8108bf894a9400ecd0930c40c
font_06_cff_off0001cba0.bin pdf-font-stream PDF embedded font (cff) at offset 0x1CBA0 2026 bytes
SHA-256: 498107d4b463cdfaabb7ecb0de303a1fd3753cd0475826d8151726b62a86cbb1
font_07_cff_off0001d6c2.bin pdf-font-stream PDF embedded font (cff) at offset 0x1D6C2 1370 bytes
SHA-256: 6b20e84459271e0cdfae9863860320d5b0fe24a40f52c5aa56fd600bf142e820
font_08_cff_off0001e196.bin pdf-font-stream PDF embedded font (cff) at offset 0x1E196 3996 bytes
SHA-256: c5675bd2f2b586cbf48ee24f95e1cf91eec1b4928c28c92220efce9ec4db3e29
font_11_cff_off000239a9.bin pdf-font-stream PDF embedded font (cff) at offset 0x239A9 1230 bytes
SHA-256: fbf22266dae0292a560fe4992b55ae8d9a60e5393b8105c8e8d7d4434902074f
font_13_cff_off000246b7.bin pdf-font-stream PDF embedded font (cff) at offset 0x246B7 2550 bytes
SHA-256: 755b31802bfcbe5da85fa3b6417005821fa046390579475e59a1b7e221fd17f2
font_15_cff_off00026f6a.bin pdf-font-stream PDF embedded font (cff) at offset 0x26F6A 2951 bytes
SHA-256: ce12ce1ce9ee146def1a9a0aa879316c8283c74b0dab40de60412666b768231d
font_17_sfnt_off0002b4ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B4EC 52108 bytes
SHA-256: 80383e85181b7288bd3f68d71356b7e2ef2e1f0ba00d93e81908469c104a18d9
font_21_sfnt_off0004f70a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4F70A 23432 bytes
SHA-256: 2722878b19761e7a433e1ca6f32e7f9fe9cccce4136877b3beb9040f23bd4b18