MALICIOUS
536
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
The PDF file contains JavaScript that triggers a launch action for cmd.exe, exploiting CVE-2010-1240. This action is paired with the `this.exportDataObject` API, indicating an attempt to drop and execute an embedded payload. The embedded artifact was detected by ClamAV as a Windows executable payload, further confirming its malicious nature.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 12
-
Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
-
ClamAV: Pdf.Tool.Agent-1388586 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Tool.Agent-1388586
-
Launch action critical PDF_LAUNCHPDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
-
Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOADPDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
-
/Launch action target: cmd.exe critical PDF_LAUNCH_COMMANDPDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
-
Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCHAn /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
-
/Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JSPDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.zeustech.net/ Referenced by PDF JavaScript
- http://]hostname[:port]/pathIn extracted file (pdf)
- http://www.apache.org/Referenced by PDF JavaScript
Extracted artifacts 16
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
pdf |
pdf-embedded-file | PDF EmbeddedFile object 81 at offset 0x1BF2C | 73802 bytes |
SHA-256: a6bbdc48e40c4901663957c6adddf4900ebe60030524a71f25b8a4a453e373d3 |
|||
|
Detection
ClamAV:
Win.Trojan.MSShellcode-6360730-0
Obfuscation or payload:
likely
actual_type=PE; declared_or_context_type=PDF; filename=pdf; kind=pdf-embedded-file Static shellcode analysis found candidate code region(s). Indicators: SC_PEB_ACCESS, SC_STR_GETPROCADDRESS Static shellcode analysis recovered API/import strings: kernel32.dll, advapi32.dll, KERNEL32.DLL, ADVAPI32.DLL, LoadLibraryA, GetProcAddress
|
|||
javascript_obj0082_000.js |
pdf-javascript-stream | PDF /JS object 82 at offset 0x26D09 | 49 bytes |
SHA-256: 135d8ff085921b81e04dc360543078fa4091eb102c6c0edfa69b9c2e8675d290 |
|||
Preview scriptFirst 1,000 lines of the extracted script
this.exportDataObject({ cName: "", nLaunch: 0 });
|
|||
font_00_sfnt_off000054bc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x54BC | 8824 bytes |
SHA-256: a82a400238dc1f59ca8236f335b6b04d41c788d85c38de3249bceb700897edec |
|||
font_01_sfnt_off0000690e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x690E | 15596 bytes |
SHA-256: cbff779555ef3ae870c0e7f235ed61b6a7546c53a1d6e652906faf352c86598d |
|||
font_02_sfnt_off0000910c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x910C | 15920 bytes |
SHA-256: 1c9f93d767c1415769b678b202d8a321f1e84380648d002a81b0a3fd9f0542f8 |
|||
font_03_sfnt_off0000b9f3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB9F3 | 10804 bytes |
SHA-256: f431964c97f3a27ac02a1933773f7b4bd697b6046a4e4804e0f27d3ae28b9529 |
|||
font_04_sfnt_off0000d2e8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD2E8 | 23324 bytes |
SHA-256: 0e262d74664c7b028c8a047814f1dfa545dc2779896d77a78da5add17627e280 |
|||
font_05_sfnt_off0000feb8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFEB8 | 35748 bytes |
SHA-256: b79c34b8c16753d440981f3a60751a2e5cb4a2820781f5cafaad2d4dc179db6d |
|||
font_06_cff_off0001484e.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x1484E | 575 bytes |
SHA-256: a9155ff9f0789eb883e595b77608d44acddf2189f9ba72b6afe6397c475d6172 |
|||
font_07_cff_off00014b6d.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x14B6D | 1681 bytes |
SHA-256: 78948f054c179a4f81ed70969773c36897ebd3f2ad8b29887b6396ea61fe801e |
|||
font_08_cff_off000152bb.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x152BB | 2401 bytes |
SHA-256: cfcf7fe0f8af0f40ad07183b90839c8fb7d77515d36ab6c8755c767bd9cc24ba |
|||
font_09_cff_off00015bc0.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x15BC0 | 623 bytes |
SHA-256: f893ce13e1bf2fe2e6458197afc13ec7ca9b26bd2b68c9fbc92241d4a221b3b9 |
|||
font_10_cff_off00015f16.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x15F16 | 3166 bytes |
SHA-256: 45c4295253fc75b426f2347c277db59c28335727e51c8db0ef7740076294be3b |
|||
font_11_cff_off00016be1.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x16BE1 | 8979 bytes |
SHA-256: 797a293324e72ab2ae1e64f3f4c835f7f8daa34dc3257ae8ab7bc86470a95f7a |
|||
font_12_cff_off0001850b.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x1850B | 666 bytes |
SHA-256: f0482c88e2cf483e40de3e77eec38fc5a2f9916e2e29b93077c7f60c9f3913c6 |
|||
font_13_cff_off0001886b.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x1886B | 1018 bytes |
SHA-256: 6419487e1ec6d6618ceb3d7a4618766fa244b541dbfaca36ea79ead0e3c58e5b |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.