Malicious PDF / .EXE — malware analysis report

Static analysis result for SHA-256 f4531a3749112820…

MALICIOUS

PDF / .EXE

2.62 MB First seen: 2026-05-10
MD5: 1c73bbef2e1fa743f48fde70a02b7eb0 SHA-1: 63a3ebcca28f71287fe79fc2ca058cc2344192c1 SHA-256: f4531a3749112820ffc2f736884502f5e8fd3d815c5d8f91afccd9cd49e4675a
290 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The file is identified as a malicious PDF containing an embedded Windows executable payload. Heuristics indicate it's a potential RCE backdoor and a malformed exploit stream. The embedded executable was detected by ClamAV as Win.Trojan.Print-2 and Win.Trojan.Krile-4, suggesting it is a known trojan. The PDF likely serves as a delivery mechanism for this payload.

Machine Learning

  • Nyx PDF Classifier clean score 0.0012

Heuristics 7

  • ClamAV: Win.Trojan.Print-2 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Win.Trojan.Print-2
  • PHP webshell / backdoor source critical WEBSHELL_PHP
    The file contains PHP server-side code with the signature of a webshell/backdoor (request input fed to a command/code-exec sink with a decoder/second sink (RCE backdoor)). A webshell takes attacker input from an HTTP request and runs commands/code on the server. Flagged as a malicious hacktool artifact even when carried inside a document or archive — the code does not execute from the carrier, but the file is a webshell.
  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • String.fromCharCode low PDF_FROMCHARCODE
    String.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules.
    Matched line in script
     key = String.fromCharCode(keycode).toLowerCase();
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.oisv.com In PDF document text
    • http://www.dynamicpad.org/In PDF document text
    • http://www.rudenko.com/In PDF document text
    • http://www.rudenko.com/robosoft/upgrade_prog.htmlIn PDF document text
    • http://www.rudenko.com/sites/In PDF document text
    • http://www.asp-shareware.org/padIn PDF document text
    • http://www.wingsofdarkness.net/php/index.phpIn PDF document text
    • http://www.BoltBait.comIn PDF document text
    • http://www.dmashton.co.uk/In PDF document text
    • http://www.xdp.it/cximage.htmIn PDF document text
    • http://www.icsharpcode.net/OpenSource/SharpZipLib/Default.aspxIn PDF document text
    • http://www.sjbrown.co.uk/?code=squishIn PDF document text
    • http://www.pinvoke.comIn PDF document text
    • http://www.oxygen-icons.org/In PDF document text
    • http://www.everaldo.com/crystal/In PDF document text
    • http://www.huddletogether.comIn PDF document text
    • http://huddletogether.com/projects/lightbox/In PDF document text
    • http://www.macecraft.com/share/lightbox/loading.gifIn PDF document text
    • http://www.faqts.com/knowledge_base/view.phtml/aid/1602//functionIn PDF document text
    • http://simon.incutio.com///functionIn PDF document text
    • http://www.macecraft.com/images/images-2/arrow.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/header.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/textfield_bg.gifIn PDF document text
    • http://www.macecraft.com/images/images-2/tabBgNew.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/user-rating-caption.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/user-rating-body.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/commonbox1-background.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/commonbox1-caption.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/commonbox1-body.pngIn PDF document text
    • http://www.macecraft.com/images/images-2/commonbox1-foot.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/button1.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/list-icon.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/commonbox2-body.jpgIn PDF document text
    • http://www.macecraft.com/ver2/images/emailbox.jpgIn PDF document text
    • http://www.macecraft.com/ver2/images/table_heading.jpgIn PDF document text
    • http://www.macecraft.com/images/images-2/tabBgNew2.jpgIn PDF document text
    • http://illusionaryz.deviantart.com}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
    • http://www.BoltBait.com}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
    • http://www.dmashton.co.uk/}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
    • http://www.xdp.it/cximage.htm}}}\f0\fs18In extracted file (embedded_pdf_00166000.exe)
    • http://www.icsharpcode.net/OpenSource/SharpZipLib/Default.aspx}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
    • http://www.sjbrown.co.uk/?code=squish}}}\b\f0\fs18In extracted file (embedded_pdf_00166000.exe)
    • http://www.pinvoke.com}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
    • http://www.oxygen-icons.org/}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
    • http://www.everaldo.com/crystal/}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
    • http://www.faqts.com/knowledge_base/view.phtml/aid/1602In extracted file (embedded_pdf_00166000.exe)
    • http://simon.incutio.com/In extracted file (embedded_pdf_00166000.exe)
    • http://www.monotype.comhttp://www.monotype.com/html/type/license.htmlIn extracted file (font_00_sfnt_off00117a3e.bin)
    • http://mydomain.com/dp/In PDF document text
    • http://illusionaryz.deviantart.comIn PDF document text
    +10 more URL(s)
🗂 Part of campaign: buchung.pl 5 samples

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_00166000.exe embedded-pe PDF raw PDF bytes PE payload at offset 0x166000 1284096 bytes
SHA-256: 16136261e629838a327ad9777a40f35e1d5f277269937b1fec0e2dd83ed22e18
Detection
ClamAV: Win.Trojan.Krile-4
Obfuscation or payload: likely
actual_type=PE; declared_or_context_type=PDF; filename=embedded_pdf_00166000.exe; kind=embedded-pe Carved artifact contains 2 shell/COM execution token(s).
font_00_sfnt_off00117a3e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x117A3E 34992 bytes
SHA-256: aa200be6d4324263de453df695a258f4a0f764b51a48d1d42ef82a5d1d1e26b2
font_01_sfnt_off0011cb1a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11CB1A 1164 bytes
SHA-256: bb467a1c790e72582b417d7fd79ca9f536e5067f5fa6fdc7f620c2d339792a1b
font_02_sfnt_off0011d04e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11D04E 37820 bytes
SHA-256: 33a060a94d55f5f175c301c82e07d1b78ade08759c89e0b7cedb9c353bc6f860