Malicious PDF — malware analysis report

Static analysis result for SHA-256 7237224343bdbdda…

MALICIOUS

PDF

18.5 KB
MD5: 16fef4b2597594b4844dcbd2fd269b43 SHA-1: d7934be7a778f887298ff3a47a15f0fb745b1f57 SHA-256: 7237224343bdbdda87ad9f4568c6301f1e6d63121af4a1278f12f9772cae3c6d
270 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.003 Windows Command Shell

The PDF file is malformed and contains an OpenAction that triggers a launch action. This launch action targets cmd.exe, indicating an attempt to execute commands on the system. The presence of an embedded script payload further suggests the file is designed to download and execute additional malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 5

  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Malformed PDF header with no object graph high PDF_MALFORMED_NO_OBJECT_GRAPH
    File starts with a PDF header but contains no indirect objects, xref table/stream, or startxref pointer. This is not a normal renderable PDF and can indicate parser fuzzing, evasion, or a corrupt exploit test case rather than benign content.
  • OpenAction trigger high PDF_OPENACTION
    PDF has an /OpenAction that launches, submits, or opens an external target
  • Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.