Malicious PDF — malware analysis report

Static analysis result for SHA-256 62028ce77d47b1e8…

MALICIOUS

PDF

9.8 KB Created: 2010-07-06 21:04:53 Authoring application: Virtual PDF Printer - www.go2pdf.com (via Virtual PDF Printer1.01) First seen: 2026-05-11
MD5: cbf5feaee91590c1089d7f21162b2b72 SHA-1: f012aa20e818dced5e8cc69ebf971506942385eb SHA-256: 62028ce77d47b1e82ebc65aa5c2d9eba2f557626a507d1b7ea787fd5ba3a25a1
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains an embedded URI pointing to www.go2pdf.com, which is flagged as suspicious by ML classifiers. While no scripts were explicitly extracted, the presence of an embedded URI and the ML detection suggest a potential attempt to redirect the user to a malicious site. The document body contains garbled text and a 'TERMS OF SERVICE' string, which may be part of a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8635

Heuristics 5

  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.go2pdf.com PDF link annotation

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00001149.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1149 10133 bytes
SHA-256: 8124686213b7604d121e95278a4957cb228ae494fe3c8ce47c7450edfd38dee4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
actual_type=PE; declared_or_context_type=PDF; filename=stream_001_off00001149.bin; kind=decompressed-pdf-stream