Malicious PDF — malware analysis report

Static analysis result for SHA-256 32e0665020edf8c0…

MALICIOUS

PDF

2.42 MB Created: Tue Dec 11 09:00:56 2007 Authoring application: LaTeX + dvips (via ESP Ghostscript 815.04)
MD5: e4604171deba703395fce315535dda7a SHA-1: 75f65770c81ed2db18877d8b6258d7fbe7ef1218 SHA-256: 32e0665020edf8c080a37985f2cdd9e0186526b39cb5ed99a0447fe7b2b017c2
498 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1059.003 Windows Command Shell T1105 Ingress Tool Transfer

The PDF contains a critical launch action that executes cmd.exe with parameters designed to download and run a secondary payload. This is further supported by a critical heuristic indicating CVE-2010-1240 exploitation and a high-confidence ML classifier flagging the PDF as malicious. The embedded artifact 'calc3book.pdf' was detected by ClamAV as Win.Trojan.Rozena-131, indicating it is a malicious executable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9838

Heuristics 14

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\calc3book.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
    An /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
  • ClamAV: Pdf.Tool.Agent-1388586 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Tool.Agent-1388586
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • /Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JS
    PDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • External URI info PDF_URI
    PDF contains an external URL action
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.mecmath.net
    • http://www.gnuplot.info/download.html

Extracted artifacts 31

Files carved from inside the sample during analysis.

FilenameKindSourceSize
calc3book.pdf
e3ac8677f780847315940ad3b09c4db03bd71df4475c4813ad0d7287ae267bf9
pdf-embedded-file PDF EmbeddedFile object 2077 at offset 0x26573B 37888 bytes
Detection
ClamAV: Win.Trojan.Rozena-131
Obfuscation or payload: unlikely
javascript_obj2078_000.js
07a0427d5198844301f8911323317db04040799ce1bb1a99871a6b087ed2ca30
pdf-javascript-stream PDF /JS object 2078 at offset 0x26A42C 58 bytes
font_00_cff_off00231028.bin
9bc1a73107ed6eb87511d7adcd2753b0f033d0aa5b8bc88934ce133a2b26f152
pdf-font-stream PDF embedded font (cff) at offset 0x231028 9191 bytes
font_01_cff_off00232df6.bin
f5b4cc67b54d266ce521794f9311e9993b8bdf4fe553407f9d5821af2fa0d549
pdf-font-stream PDF embedded font (cff) at offset 0x232DF6 9384 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.40, consistent with packed or encrypted content.
font_02_cff_off00234ccf.bin
b70b0b9bde1212c0d64edd8a1f10ea2a150673f1a7b7fa2602b66b882ed6a4e8
pdf-font-stream PDF embedded font (cff) at offset 0x234CCF 495 bytes
font_03_cff_off00234f29.bin
3975fbf8fd8d40c15909cccaa21deb4a624d698fb7025e1aafc4188c80ec53d8
pdf-font-stream PDF embedded font (cff) at offset 0x234F29 1801 bytes
font_04_cff_off0023553f.bin
f8c821c7b9382e1b3ec0efc3270de05bc79d69be811f0c1217d433f837652a9b
pdf-font-stream PDF embedded font (cff) at offset 0x23553F 599 bytes
font_05_cff_off002357f3.bin
7087fd89bb69641fab6b770d2d130fe8753d4a0f9daace71a59eaaf58550c21f
pdf-font-stream PDF embedded font (cff) at offset 0x2357F3 3221 bytes
font_06_cff_off00236404.bin
f3f42d7e19e1fc9d011a964cb438d6a35b62db69033b34ac8c8c3c39a1cf08d6
pdf-font-stream PDF embedded font (cff) at offset 0x236404 3402 bytes
font_07_cff_off002370aa.bin
d2406d1098a9ead2626062722e756ba35d14ba0b934cfeaf92e635f81c042923
pdf-font-stream PDF embedded font (cff) at offset 0x2370AA 3483 bytes
font_08_cff_off00237b15.bin
352daa25a3417454a8f5df6d6009624d0bbb53c3206895b6d97ca096d6a96d29
pdf-font-stream PDF embedded font (cff) at offset 0x237B15 315 bytes
font_09_cff_off00237cc7.bin
4c9ae5843488e618a2218c3f7915deb877d86923e703e5138b9778d4401ea1b7
pdf-font-stream PDF embedded font (cff) at offset 0x237CC7 1376 bytes
font_10_cff_off00238239.bin
d4ed368816c622ed1be6291adc2dce1e57b39cf3bfb046813d1559deda23fbcb
pdf-font-stream PDF embedded font (cff) at offset 0x238239 1899 bytes
font_11_cff_off00238953.bin
aab32bf46ad7294a389f591129676fe26661405956e25cb3cba0a6eec2ace0b5
pdf-font-stream PDF embedded font (cff) at offset 0x238953 5589 bytes
font_12_cff_off002399eb.bin
4710b5fb8318b3f73a7c46c4ca3484a24e040fb7e38d3fc5003296b9403ab45e
pdf-font-stream PDF embedded font (cff) at offset 0x2399EB 5067 bytes
font_13_cff_off0023aad7.bin
75d8b940f569fa340991e3932ff53a2d262b6c996bafdc99fa8d82c5f08768a0
pdf-font-stream PDF embedded font (cff) at offset 0x23AAD7 2530 bytes
font_14_cff_off0023b1f4.bin
7c18ed2e92a8527f4bef894cae0ddd667c1d338503759f266295eacf76614632
pdf-font-stream PDF embedded font (cff) at offset 0x23B1F4 471 bytes
font_15_cff_off0023b43a.bin
1e5a55ec1b9ee4beb3fda121174742c6d4429bf8903302b7de9e292122744207
pdf-font-stream PDF embedded font (cff) at offset 0x23B43A 716 bytes
font_16_cff_off0023b6ec.bin
cee507c14c32bfb627ecdef2c9e0b4b628d16fae2c73023844169fc7ff82fc5b
pdf-font-stream PDF embedded font (cff) at offset 0x23B6EC 658 bytes
font_17_cff_off0023b9f3.bin
45ac65a45b551fa50651987621a9aee1cf0555b2bd5ced7a5fec2e02e66ff426
pdf-font-stream PDF embedded font (cff) at offset 0x23B9F3 973 bytes
font_18_cff_off0023bdef.bin
fc0ee3a98e64ec3034d2f5d69967c0120ee5b96832bd8524d7dcefdc92ec5ba2
pdf-font-stream PDF embedded font (cff) at offset 0x23BDEF 392 bytes
font_19_cff_off0023bfa0.bin
900eb8b8492e7722366efab88ce10d3bfe57f85498f7270469cb8686accac947
pdf-font-stream PDF embedded font (cff) at offset 0x23BFA0 202 bytes
font_20_cff_off0023c0e1.bin
c20a2b0299486f355642cc5eb33a26fddb3de689a104fc0461172506536a56f2
pdf-font-stream PDF embedded font (cff) at offset 0x23C0E1 2635 bytes
font_21_cff_off0023c658.bin
7cc7defa34db29e9dd0d9552ad0caeb585063f1bfbae6f574996cdf2c511f428
pdf-font-stream PDF embedded font (cff) at offset 0x23C658 411 bytes
font_22_cff_off0023c860.bin
aeeb5237e565987c12a227a2171410309ec8fcc7cf6024c92b86cd0c00b63466
pdf-font-stream PDF embedded font (cff) at offset 0x23C860 7138 bytes
font_23_cff_off0023e1bb.bin
3b8d9aff588b86d91d67ad4ac6c11c025961dc974cf3b58d409fdb2403aa5d7d
pdf-font-stream PDF embedded font (cff) at offset 0x23E1BB 1075 bytes
font_24_cff_off0023e602.bin
c698b62ee084c72d4ba1ca6e9715b3fab1b8842342f99602f50f67557915a0c6
pdf-font-stream PDF embedded font (cff) at offset 0x23E602 1267 bytes
font_25_cff_off0023eb39.bin
72d7982b75a7d3b6686773ce81d0be2114d5e9a92426ab9f1c04726e281e9818
pdf-font-stream PDF embedded font (cff) at offset 0x23EB39 2133 bytes
font_26_cff_off0023f392.bin
77dd17f1e04581030a3f52c24177fbad1149e11738a2ee079ccb9041d146d485
pdf-font-stream PDF embedded font (cff) at offset 0x23F392 367 bytes
font_27_cff_off0023f550.bin
dc7ddb165d69a276e4ff7e704dc801afe292c435bbb52b661d6ff4bad61b0c9e
pdf-font-stream PDF embedded font (cff) at offset 0x23F550 10904 bytes
font_28_cff_off00241876.bin
24e0b0d492e2d8270d20b0b01ce0cd42ca54f6ea1c999f2b45495d9207f68dcf
pdf-font-stream PDF embedded font (cff) at offset 0x241876 2796 bytes