Malicious PDF — malware analysis report

Static analysis result for SHA-256 59ffa3607a30be6a…

MALICIOUS

PDF

3.30 MB
MD5: 84306ea81d6b918c67d8c6a44f2fe75d SHA-1: afd45445f8270e9b59749ca8cf5bc1d0f10ae7f0 SHA-256: 59ffa3607a30be6ae10c4991da01e70566c83b5e26200a0efa18465c4753f538
454 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell T1204.002 Malicious File T1105 Ingress Tool Transfer

The PDF file contains a critical launch action that executes cmd.exe, exploiting CVE-2010-1240. This command execution is paired with JavaScript that uses the exportDataObject API to drop an embedded file. This embedded file, named 'test.pdf', is detected by ClamAV as a Windows executable (Win.Trojan.MSShellcode-7), indicating it is likely a second-stage payload. The ML classifier also flagged the PDF with a high probability of being malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9863

Heuristics 11

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\test.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
    An /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
  • ClamAV: Pdf.Dropper.Agent-7263170-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-7263170-0
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • /Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JS
    PDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xap/1.0/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/g/img/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
    • http://ns.adobe.com/illustrator/1.0/
    • http://ns.adobe.com/pdf/1.3/

Extracted artifacts 17

Files carved from inside the sample during analysis.

FilenameKindSourceSize
test.pdf
bdda30ef6457903c8e3a2acb43dc9497264a0b2bd5f00ea06ea55f1541a8d67e
pdf-embedded-file PDF EmbeddedFile object 350 at offset 0x342D0A 73802 bytes
Detection
ClamAV: Win.Trojan.MSShellcode-7
Obfuscation or payload: unlikely
javascript_obj0351_000.js
b1a09f919e0f5d1c1d284849c9af93bae6fd1411634dfdc491e126f9cd327f3f
pdf-javascript-stream PDF /JS object 351 at offset 0x34DA44 53 bytes
stream_006_off0009c917.bin
35f401731df11a4eba3502af632e51d68bc394bcb7d34632a331c1ba3f4a0bf6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9C917 557168 bytes
stream_018_off0010b3af.js
2667a6b304af91fd127df565b6cd1991dc8e20a61551362539e16ea8b17d46a8
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x10B3AF 29816 bytes
icc_00_off00009bd6.icc
2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
pdf-icc-profile PDF ICC profile at offset 0x9BD6 3144 bytes
icc_01_off0000a6aa.icc
283e482d9b10db98fb7df2f6ef4bdf4ddf8de5a07d2c7530cc361ec4b29ed39a
pdf-icc-profile PDF ICC profile at offset 0xA6AA 1960 bytes
icc_03_off001efb44.icc
8dcdb16b7a0110cc991d12060a072d2a2214c50547f66afbb36cb9870e7cef17
pdf-icc-profile PDF ICC profile at offset 0x1EFB44 6924 bytes
font_00_sfnt_off00324e8e.bin
b2693b4c0efedd63f45cb5ab809349b68c0e82340b85cc34ad2e0dba8b28b854
pdf-font-stream PDF embedded font (sfnt) at offset 0x324E8E 19212 bytes
font_01_sfnt_off00327bbd.bin
2b1c42ed29d356f3c67ac77056dc894809ca1952f6d569da971590e835355355
pdf-font-stream PDF embedded font (sfnt) at offset 0x327BBD 14028 bytes
font_02_sfnt_off00329f59.bin
c1b1e73d514ae2961b66cf605e724f7369cc05ab793a5eeb93a66ad251ad49cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x329F59 41944 bytes
font_03_sfnt_off003313e7.bin
8811fc14ca1f6d8deb25675ab41131b83199804df3e1d62bbefdf08c87f7b5d1
pdf-font-stream PDF embedded font (sfnt) at offset 0x3313E7 30868 bytes
font_04_sfnt_off00336852.bin
fb1d27366889a9a4af6664146871b86bacac9d9174b61bf4a91c88b523b02cf6
pdf-font-stream PDF embedded font (sfnt) at offset 0x336852 3704 bytes
font_05_sfnt_off0033737f.bin
9db7a34473755f4e44dfe0184bb0c54aa2c5886866ac9fff889945e1e8dedb21
pdf-font-stream PDF embedded font (sfnt) at offset 0x33737F 9324 bytes
font_06_sfnt_off00339050.bin
1c74f17a06e5311daa73192132772fc38a0a2c466fdc47cb0297d3cc8ae9fec1
pdf-font-stream PDF embedded font (sfnt) at offset 0x339050 11984 bytes
font_07_sfnt_off0033b428.bin
fcd01e39cf402c77ac2b1e8f993588b297a065ac03f8c2a4d12a72366f2c79c1
pdf-font-stream PDF embedded font (sfnt) at offset 0x33B428 28576 bytes
font_08_sfnt_off0033f38d.bin
7d0ee788f927ed1bbeb3313e6f0b0f90116dec88e606d0951123e8367cf47375
pdf-font-stream PDF embedded font (sfnt) at offset 0x33F38D 6780 bytes
font_09_sfnt_off00340766.bin
4ae0abeed37926d3cf47be523bec004d2e547bcee670af48e58120435aa534ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x340766 3124 bytes