Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce7010b5f47aa606…

MALICIOUS

PDF

8.98 MB First seen: 2026-05-13
MD5: acac50cfc10d66c2e2e07b5bece04878 SHA-1: 23dc13995e68d232f6486e1098efa19706516823 SHA-256: ce7010b5f47aa606ed1c2e13c5bece5fded4291dfe1dbeecbddc25226756d629
72 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

This PDF sample was flagged as malicious by an ML classifier and exhibits high-risk heuristics. It contains an embedded JavaScript stream and is encrypted with an /OpenAction, indicating an attempt to hide malicious content and execute it upon opening. The document body is unreadable, suggesting it serves as a lure, and the presence of JavaScript points to an attempt to download and execute a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7362

Heuristics 2

  • Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYou In PDF document text
    • http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
    • http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
    • http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_163_off008ce3f8.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8CE3F8 20232 bytes
SHA-256: 3db4b42707d912eb467dc3e1fa0bf6886f6a15e37a5658599e0140b38e0df2ba
stream_166_off008f1b89.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8F1B89 24864 bytes
SHA-256: 4954c9d5cd8f64d046a89b56e39c3a0e634eab8983629f1848d00471a093ab8b
font_00_sfnt_off008b0bcb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8B0BCB 169476 bytes
SHA-256: a6eacb5f4c318f191f5c7ef56b8a9d24965db43dd12e86dc8eafc984e1163d47
font_01_sfnt_off008c452d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8C452D 177252 bytes
SHA-256: c36c6921e42f06a577d06872c5da42d1d6cd6e46526e39abd6a88dd4b5aae47c