Malicious PDF — malware analysis report

Static analysis result for SHA-256 dae9bcefb4d2a325…

MALICIOUS

PDF

318.6 KB Created: 2010-02-08 18:51:50 +01:00 Authoring application: TeX (via pdfTeX-1.40.3) First seen: 2026-05-10
MD5: 2183c7ae4149c7075e40a8f759bf285f SHA-1: 1c9cb274bda2ba1c6d2471c88f2906713c1eb65d SHA-256: dae9bcefb4d2a3252d90f3d24310a17fd85a510ca04d816243821bcc6ac7f2cb
660 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript T1105 Ingress Tool Transfer

The PDF file contains embedded JavaScript that utilizes the `exportDataObject` function to launch `cmd.exe`. This command is used to execute a dropped payload, identified as a Windows executable by ClamAV (Win.Trojan.Rozena-736). The PDF itself is detected as malicious by ClamAV (Pdf.Tool.Agent-1388586). The embedded JavaScript and the launch action indicate a clear intent to execute a secondary payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9888

Heuristics 16

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • ClamAV: Pdf.Tool.Agent-1388586 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Tool.Agent-1388586
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\polipo.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
    An /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
  • Suspicious extracted artifact critical EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • /Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JS
    PDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAM
    Document repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://internet.junkbuster.com/ In PDF document text
    • http://www.privoxy.org/In PDF document text
    • http://localhost:8123/Referenced by PDF JavaScript
    • http://localhost:8123/���In PDF document text
    • http://localhost:8123/polipo/���In PDF document text
    • http://localhost:8123/polipo/config?���In PDF document text
    • http://localhost:8123/polipo/status?���In PDF document text
    • http://localhost:8123/polipo/servers?���In PDF document text
    • http://localhost:8123/polipo/index?���In PDF document text
    • http://localhost:8123/polipo/index?http://www.microsoft.com/Referenced by PDF JavaScript
    • http://localhost:8123/polipo/recursive-index?���In PDF document text
    • http://zipper.paco.net/~igor/oops.eng/In PDF document text
    • http://localhost:8123/polipo/Referenced by PDF JavaScript
    • http://localhost:8123/polipo/configReferenced by PDF JavaScript
    • http://localhost:8123/polipo/statusReferenced by PDF JavaScript
    • http://localhost:8123/polipo/serversReferenced by PDF JavaScript
    • http://localhost:8123/polipo/indexReferenced by PDF JavaScript
    • http://localhost:8123/polipo/recursive-indexReferenced by PDF JavaScript
    • tcp://192.168.247.133:443In extracted file (polipo.pdf)
    • http://www.opera.com/PDF link annotation
    • http://www.mozilla.orgIn PDF document text
    • http://www.debian.orgIn PDF document text
    • http://www.squid-cache.org/In PDF document text
    • http://www.apache.org/In PDF document text
    • http://www.gedanken.demon.co.uk/wwwoffle/In PDF document text
    • http://tor.eff.orgIn PDF document text
    • https://www.torproject.org/torbutton/In PDF document text
    • http://home.t-online.de/home/Moestl/In PDF document text
🗂 Part of campaign: ggobi.org 10 samples

Extracted artifacts 16

Files carved from inside the sample during analysis.

FilenameKindSourceSize
polipo.pdf pdf-embedded-file PDF EmbeddedFile object 869 at offset 0x4A9B6 37888 bytes
SHA-256: 2cee9f1fc75c499a615c724c1352cea43e258c91349b1d73aebcf4d5474b6269
Detection
ClamAV: Win.Trojan.Rozena-736
Obfuscation or payload: likely
actual_type=PE; declared_or_context_type=PDF; filename=polipo.pdf; kind=pdf-embedded-file Static shellcode analysis recovered the Metasploit stager connect-back address: 192.168.247.133:443 (reverse/x86, lab (non-routable)) Static shellcode analysis found candidate code region(s). Indicators: SC_PEB_ACCESS, SC_MSF_BIND, SC_PUSH_STRING Static shellcode analysis recovered API/import strings: GetProcAddress, ExitProcess, LoadLibraryA, VirtualAlloc
javascript_obj0870_000.js pdf-javascript-stream PDF /JS object 870 at offset 0x4F691 55 bytes
SHA-256: 9c9d4e989248221b06bb546eb2bbb6d44cb9901f7ac22e3ac95c0216f640502b
Preview script
First 1,000 lines of the extracted script
this.exportDataObject({ cName: "polipo", nLaunch: 0 });
stream_035_off0002cb8b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2CB8B 1734 bytes
SHA-256: 3f3016da3d6b20672e4a194cbe55ee85bb8421e5b1028b158e3d359d3646ca29
stream_037_off0002da02.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2DA02 1734 bytes
SHA-256: ef0150165269e05cc5aaa2bdbe90a34033fa99d0e21b27f88c9e69d613c92ab7
stream_042_off00038784.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x38784 3938 bytes
SHA-256: 35f6f377b01d3719eaf7a4c286d557ee14d92551ad2b805ab2b1027a04dc913a
stream_046_off0003c988.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3C988 15293 bytes
SHA-256: 7f915a2d2454d86c4d18929fbadd1277e41b6b002c2707f740cc71c85586f79c
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.88, consistent with packed or encrypted content.
stream_047_off0004044b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4044B 11021 bytes
SHA-256: b5bf23f7cc994344544888951bd29cc953f276b19f6cf6fbb2d21ea7d2605339
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.87, consistent with packed or encrypted content.
font_00_type1_off00029bda.bin pdf-font-stream PDF embedded font (type1) at offset 0x29BDA 12452 bytes
SHA-256: f2b8780bf36f861228c570df4f7b65c758f5faf8b43d7b0c2363e168239066de
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.87, consistent with packed or encrypted content.
font_02_type1_off0002d2c4.bin pdf-font-stream PDF embedded font (type1) at offset 0x2D2C4 1734 bytes
SHA-256: 7fa1975cfb5e221517c20cc8bc89f772ad59ad1fca5dc1ea37307406733dc851
font_04_type1_off0002e141.bin pdf-font-stream PDF embedded font (type1) at offset 0x2E141 17405 bytes
SHA-256: 7fa343986f3fd97d1c267dcd206c9387d089796aece3a580cd1c18d45efdcfaf
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.90, consistent with packed or encrypted content.
font_05_type1_off0003240d.bin pdf-font-stream PDF embedded font (type1) at offset 0x3240D 2913 bytes
SHA-256: 38ed21d120a164c314133994a40342b8575739b9669bec1d1d351dde831c93d6
font_06_type1_off00032fde.bin pdf-font-stream PDF embedded font (type1) at offset 0x32FDE 14156 bytes
SHA-256: 10561f464965b8f78840f03db39510b7041953ab7982483558ab5fa45f8dcf51
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.89, consistent with packed or encrypted content.
font_07_type1_off00036638.bin pdf-font-stream PDF embedded font (type1) at offset 0x36638 8602 bytes
SHA-256: be18758e222f05f561ab389f85ad7bdcd3232e5915d05e43677322ddcc468456
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.87, consistent with packed or encrypted content.
font_09_type1_off0003971f.bin pdf-font-stream PDF embedded font (type1) at offset 0x3971F 3634 bytes
SHA-256: c8562132561c433be11edfc8fbab9e1768be5be9bff58f934b228047c502d39e
font_10_type1_off0003a583.bin pdf-font-stream PDF embedded font (type1) at offset 0x3A583 1484 bytes
SHA-256: 86f632017c4a40ffcd0303a1f12fba71079f9d524db8f2083cc0e469dddea973
font_11_type1_off0003abc4.bin pdf-font-stream PDF embedded font (type1) at offset 0x3ABC4 7629 bytes
SHA-256: bb5ddbd42493c56c76dae04944735c340a4d0ace634bb2cd4c0065d2ee13c08b
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.86, consistent with packed or encrypted content.