Malicious PDF — malware analysis report

Static analysis result for SHA-256 32e0665020edf8c0…

MALICIOUS

PDF

2.42 MB Created: Tue Dec 11 09:00:56 2007 Authoring application: LaTeX + dvips (via ESP Ghostscript 815.04) First seen: 2026-05-11
MD5: e4604171deba703395fce315535dda7a SHA-1: 75f65770c81ed2db18877d8b6258d7fbe7ef1218 SHA-256: 32e0665020edf8c080a37985f2cdd9e0186526b39cb5ed99a0447fe7b2b017c2
558 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript T1105 Ingress Tool Transfer

The PDF file contains embedded JavaScript that utilizes the `exportDataObject` function, which is known to be used for dropping files. This action is paired with a PDF launch action targeting `cmd.exe`, indicating an attempt to execute a dropped payload. The embedded artifact `calc3book.pdf` was detected as a Windows executable by ClamAV, and further static triage flagged it as a potential Metasploit stager. The presence of `tcp://10.20.0.1:4444` suggests a command and control channel.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9838

Heuristics 13

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • ClamAV: Pdf.Tool.Agent-1388586 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Tool.Agent-1388586
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\calc3book.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
    An /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
  • Suspicious extracted artifact critical EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • /Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JS
    PDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.mecmath.net PDF link annotation
    • http://www.mecmath.net)/S/URIIn PDF document text
    • tcp://10.20.0.1:4444In extracted file (calc3book.pdf)
    • http://java.sun.com/javase/downloadsIn PDF document text
    • http://www.gnuplot.info/download.html)/S/URIIn PDF document text
    • http://fontforge.sf.netIn extracted file (font_13_cff_off0023aad7.bin)

Extracted artifacts 31

Files carved from inside the sample during analysis.

FilenameKindSourceSize
calc3book.pdf pdf-embedded-file PDF EmbeddedFile object 2077 at offset 0x26573B 37888 bytes
SHA-256: e3ac8677f780847315940ad3b09c4db03bd71df4475c4813ad0d7287ae267bf9
Detection
ClamAV: Win.Trojan.Rozena-131
Obfuscation or payload: likely
actual_type=PE; declared_or_context_type=PDF; filename=calc3book.pdf; kind=pdf-embedded-file Static shellcode analysis recovered the Metasploit stager connect-back address: 10.20.0.1:4444 (reverse/x86, lab (non-routable)) Static shellcode analysis found candidate code region(s). Indicators: SC_PEB_ACCESS, SC_MSF_BIND, SC_PUSH_STRING Static shellcode analysis recovered API/import strings: GetProcAddress, ExitProcess, LoadLibraryA, VirtualAlloc
javascript_obj2078_000.js pdf-javascript-stream PDF /JS object 2078 at offset 0x26A42C 58 bytes
SHA-256: 07a0427d5198844301f8911323317db04040799ce1bb1a99871a6b087ed2ca30
Preview script
First 1,000 lines of the extracted script
this.exportDataObject({ cName: "calc3book", nLaunch: 0 });
font_00_cff_off00231028.bin pdf-font-stream PDF embedded font (cff) at offset 0x231028 9191 bytes
SHA-256: 9bc1a73107ed6eb87511d7adcd2753b0f033d0aa5b8bc88934ce133a2b26f152
font_01_cff_off00232df6.bin pdf-font-stream PDF embedded font (cff) at offset 0x232DF6 9384 bytes
SHA-256: f5b4cc67b54d266ce521794f9311e9993b8bdf4fe553407f9d5821af2fa0d549
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.40, consistent with packed or encrypted content.
font_02_cff_off00234ccf.bin pdf-font-stream PDF embedded font (cff) at offset 0x234CCF 495 bytes
SHA-256: b70b0b9bde1212c0d64edd8a1f10ea2a150673f1a7b7fa2602b66b882ed6a4e8
font_03_cff_off00234f29.bin pdf-font-stream PDF embedded font (cff) at offset 0x234F29 1801 bytes
SHA-256: 3975fbf8fd8d40c15909cccaa21deb4a624d698fb7025e1aafc4188c80ec53d8
font_04_cff_off0023553f.bin pdf-font-stream PDF embedded font (cff) at offset 0x23553F 599 bytes
SHA-256: f8c821c7b9382e1b3ec0efc3270de05bc79d69be811f0c1217d433f837652a9b
font_05_cff_off002357f3.bin pdf-font-stream PDF embedded font (cff) at offset 0x2357F3 3221 bytes
SHA-256: 7087fd89bb69641fab6b770d2d130fe8753d4a0f9daace71a59eaaf58550c21f
font_06_cff_off00236404.bin pdf-font-stream PDF embedded font (cff) at offset 0x236404 3402 bytes
SHA-256: f3f42d7e19e1fc9d011a964cb438d6a35b62db69033b34ac8c8c3c39a1cf08d6
font_07_cff_off002370aa.bin pdf-font-stream PDF embedded font (cff) at offset 0x2370AA 3483 bytes
SHA-256: d2406d1098a9ead2626062722e756ba35d14ba0b934cfeaf92e635f81c042923
font_08_cff_off00237b15.bin pdf-font-stream PDF embedded font (cff) at offset 0x237B15 315 bytes
SHA-256: 352daa25a3417454a8f5df6d6009624d0bbb53c3206895b6d97ca096d6a96d29
font_09_cff_off00237cc7.bin pdf-font-stream PDF embedded font (cff) at offset 0x237CC7 1376 bytes
SHA-256: 4c9ae5843488e618a2218c3f7915deb877d86923e703e5138b9778d4401ea1b7
font_10_cff_off00238239.bin pdf-font-stream PDF embedded font (cff) at offset 0x238239 1899 bytes
SHA-256: d4ed368816c622ed1be6291adc2dce1e57b39cf3bfb046813d1559deda23fbcb
font_11_cff_off00238953.bin pdf-font-stream PDF embedded font (cff) at offset 0x238953 5589 bytes
SHA-256: aab32bf46ad7294a389f591129676fe26661405956e25cb3cba0a6eec2ace0b5
font_12_cff_off002399eb.bin pdf-font-stream PDF embedded font (cff) at offset 0x2399EB 5067 bytes
SHA-256: 4710b5fb8318b3f73a7c46c4ca3484a24e040fb7e38d3fc5003296b9403ab45e
font_13_cff_off0023aad7.bin pdf-font-stream PDF embedded font (cff) at offset 0x23AAD7 2530 bytes
SHA-256: 75d8b940f569fa340991e3932ff53a2d262b6c996bafdc99fa8d82c5f08768a0
font_14_cff_off0023b1f4.bin pdf-font-stream PDF embedded font (cff) at offset 0x23B1F4 471 bytes
SHA-256: 7c18ed2e92a8527f4bef894cae0ddd667c1d338503759f266295eacf76614632
font_15_cff_off0023b43a.bin pdf-font-stream PDF embedded font (cff) at offset 0x23B43A 716 bytes
SHA-256: 1e5a55ec1b9ee4beb3fda121174742c6d4429bf8903302b7de9e292122744207
font_16_cff_off0023b6ec.bin pdf-font-stream PDF embedded font (cff) at offset 0x23B6EC 658 bytes
SHA-256: cee507c14c32bfb627ecdef2c9e0b4b628d16fae2c73023844169fc7ff82fc5b
font_17_cff_off0023b9f3.bin pdf-font-stream PDF embedded font (cff) at offset 0x23B9F3 973 bytes
SHA-256: 45ac65a45b551fa50651987621a9aee1cf0555b2bd5ced7a5fec2e02e66ff426
font_18_cff_off0023bdef.bin pdf-font-stream PDF embedded font (cff) at offset 0x23BDEF 392 bytes
SHA-256: fc0ee3a98e64ec3034d2f5d69967c0120ee5b96832bd8524d7dcefdc92ec5ba2
font_19_cff_off0023bfa0.bin pdf-font-stream PDF embedded font (cff) at offset 0x23BFA0 202 bytes
SHA-256: 900eb8b8492e7722366efab88ce10d3bfe57f85498f7270469cb8686accac947
font_20_cff_off0023c0e1.bin pdf-font-stream PDF embedded font (cff) at offset 0x23C0E1 2635 bytes
SHA-256: c20a2b0299486f355642cc5eb33a26fddb3de689a104fc0461172506536a56f2
font_21_cff_off0023c658.bin pdf-font-stream PDF embedded font (cff) at offset 0x23C658 411 bytes
SHA-256: 7cc7defa34db29e9dd0d9552ad0caeb585063f1bfbae6f574996cdf2c511f428
font_22_cff_off0023c860.bin pdf-font-stream PDF embedded font (cff) at offset 0x23C860 7138 bytes
SHA-256: aeeb5237e565987c12a227a2171410309ec8fcc7cf6024c92b86cd0c00b63466
font_23_cff_off0023e1bb.bin pdf-font-stream PDF embedded font (cff) at offset 0x23E1BB 1075 bytes
SHA-256: 3b8d9aff588b86d91d67ad4ac6c11c025961dc974cf3b58d409fdb2403aa5d7d
font_24_cff_off0023e602.bin pdf-font-stream PDF embedded font (cff) at offset 0x23E602 1267 bytes
SHA-256: c698b62ee084c72d4ba1ca6e9715b3fab1b8842342f99602f50f67557915a0c6
font_25_cff_off0023eb39.bin pdf-font-stream PDF embedded font (cff) at offset 0x23EB39 2133 bytes
SHA-256: 72d7982b75a7d3b6686773ce81d0be2114d5e9a92426ab9f1c04726e281e9818
font_26_cff_off0023f392.bin pdf-font-stream PDF embedded font (cff) at offset 0x23F392 367 bytes
SHA-256: 77dd17f1e04581030a3f52c24177fbad1149e11738a2ee079ccb9041d146d485
font_27_cff_off0023f550.bin pdf-font-stream PDF embedded font (cff) at offset 0x23F550 10904 bytes
SHA-256: dc7ddb165d69a276e4ff7e704dc801afe292c435bbb52b661d6ff4bad61b0c9e
font_28_cff_off00241876.bin pdf-font-stream PDF embedded font (cff) at offset 0x241876 2796 bytes
SHA-256: 24e0b0d492e2d8270d20b0b01ce0cd42ca54f6ea1c999f2b45495d9207f68dcf