Malicious PDF — malware analysis report

Static analysis result for SHA-256 c3106f5489c1b841…

MALICIOUS

PDF

15.49 MB Created: 2026-04-13 19:05:26 +00:00 Authoring application: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 (via Skia/PDF m147) First seen: 2026-04-13
MD5: aa6d9a63d14b0ae4b9d83783ab6e6a1b SHA-1: 9ecf3962db337cdf5ebbdec5097506873d55a39d SHA-256: c3106f5489c1b841efdc193587b79e9f434f2410e851971f3539b9a043ed1ef3
134 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell

The PDF contains a high number of streams, suggesting obfuscation or heap spraying techniques. The document body mentions 'Sliver C2', indicating potential command and control activity. A key heuristic indicates a 'Password-protected archive handoff', suggesting the document is a lure to obtain a password for a malicious archive. The presence of 'curl https://' in the document text points to the potential use of command-line tools for downloading further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7150

Heuristics 5

  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://github.com/BishopFox/sliver
    • https://github.com/BishopFox/
    • https://sliver.sh/install
    • https://github.com/BishopFox/sliver/wiki/Port-Forwarding
    • https://github.com/BishopFox/sliver/releases/tag/v1.1.0
    • https://github.com/sliverarmory/armory
    • https://github.com/skelsec/pypykatz
    • https://github.com/GhostPack/Rubeus
    • https://github.com/gentilkiwi/mimikatz
    • https://adsecurity.org/?p=1729
    • https://github.com/salesforce/jarm
    • https://blog.cobaltstrike.com/2020/12/08/a-red-teamer-plays-with-jarm/
    • https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90008
    • https://www.cybereason.com/blog
    • https://www.cybereason.com/blog/category/all
    • https://www.cybereason.com/blog/category/research
    • https://www.cybereason.com/blog/category/podcasts
    • https://www.cybereason.com/blog/category/webinars
    • https://www.cybereason.com/blog/category/resources
    • https://www.cybereason.com/blog/category/videos
    • https://www.cybereason.com/blog/category/news
    • https://www.cybereason.com/
    • https://www.cybereason.com/request-a-demo
    • https://attack.mitre.org/tactics/TA0011/
    • https://attack.mitre.org/tactics/TA0002/
    • https://attack.mitre.org/techniques/T1059/003/
    • https://attack.mitre.org/tactics/TA0004/
    • https://attack.mitre.org/techniques/T1548/002/
    • https://attack.mitre.org/techniques/T1134/
    • https://attack.mitre.org/tactics/TA0005/
    • https://attack.mitre.org/techniques/T1055/
    • https://attack.mitre.org/tactics/TA0008/
    • https://attack.mitre.org/techniques/T1569/002/
    • https://attack.mitre.org/techniques/T1571/
    • https://attack.mitre.org/techniques/T1090/
    • https://www.ncsc.gov.uk/files/Advisory%20Further%20TTPs%20associated%20with%20SVR%20cyber%20actors.pdf
    • https://www.proofpoint.com/uk/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity
    • https://www.proofpoint.com/us/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity
    • https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control
    • https://en.wikipedia.org/wiki/DMZ_\(computing\
    • https://0x00-0x00.github.io/research/2018/10/31/How-to-bypass-UAC-in-newer-Windows-versions.html
    • https://www.wireguard.com/
    • http://attack.mitre.org/techniques/T1548/002/
    • https://attack.mitre.org/techniques/T1218/003/
    • https://attack.mitre.org/techniques/T1550/003/
    • https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a/
    • https://ti.defender.microsoft.com/articles/b1406335
    • https://www.cybereason.com/blog/ttp-briefing-q4-2025
    • https://www.cybereason.com/blog/fake-installer-valleyrat
    • https://www.cybereason.com/blog/identity-beyond-2026-incident-response-predictions
    +30 more URL(s)

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off00024cca.bin
5f2661b34e824f9e1da534a831db6cc80a941154eaeeb01516400a5085330574
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x24CCA 2260800 bytes
icc_00_off0000019d.icc
d9f822e8083f2f4d1c91e887454be5f75e8c7144b2853408f361e3c4a7a6b36d
pdf-icc-profile PDF ICC profile at offset 0x19D 536 bytes
font_00_sfnt_off00eafa86.bin
e662f4c2cecc22b66c4a2829360aebf8eb16b181bb8fe7ad5c8d548986165de3
pdf-font-stream PDF embedded font (sfnt) at offset 0xEAFA86 4984 bytes
font_01_sfnt_off00eb0d1d.bin
a64128ad1f51e291e4bb00da85865a3fe3ba13f62461398b0d0933cf4d7375fa
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB0D1D 8336 bytes
font_02_sfnt_off00eb238d.bin
61b4ab50c48bc1645cd9927de78b591c0231a247606027800341e09d23c5e138
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB238D 8936 bytes
font_03_sfnt_off00eb3492.bin
67fd053778864a622fa421c337ef48f6cd900de5e4efb9c313c5f8cd410513f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB3492 5988 bytes
font_04_sfnt_off00eb4665.bin
cb4fe820dcb743931fe792c3df82c37f3d7bdc55c520acc8bdc53f5b61a41f8b
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB4665 5404 bytes
font_05_sfnt_off00eb98d7.bin
5ad2bd21c9b16a4ba02bd7432dd474247eed8c39081c5ba103f8221e2d7d6e78
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB98D7 3712 bytes
font_06_sfnt_off00eebf16.bin
ef15a1c6e955d84dd750deafb6a10417fc173377250e7aec6c2b18590b1bee46
pdf-font-stream PDF embedded font (sfnt) at offset 0xEEBF16 3624 bytes
font_07_sfnt_off00eff533.bin
dded656c451ef444c7effbc327b878f11302a295f7e2f2c9d51a177f46746881
pdf-font-stream PDF embedded font (sfnt) at offset 0xEFF533 2324 bytes