MALICIOUS
290
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The file is identified as a malicious PDF containing an embedded Windows executable payload. Heuristics indicate it's a potential RCE backdoor and a malformed exploit stream. The embedded executable was detected by ClamAV as Win.Trojan.Print-2 and Win.Trojan.Krile-4, suggesting it is a known trojan. The PDF likely serves as a delivery mechanism for this payload.
Machine Learning
- Nyx PDF Classifier clean score 0.0012
Heuristics 7
-
ClamAV: Win.Trojan.Print-2 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Trojan.Print-2
-
PHP webshell / backdoor source critical WEBSHELL_PHPThe file contains PHP server-side code with the signature of a webshell/backdoor (request input fed to a command/code-exec sink with a decoder/second sink (RCE backdoor)). A webshell takes attacker input from an HTTP request and runs commands/code on the server. Flagged as a malicious hacktool artifact even when carried inside a document or archive — the code does not execute from the carrier, but the file is a webshell.
-
Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOADPDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
-
Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTHA PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
String.fromCharCode low PDF_FROMCHARCODEString.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules.Matched line in script
key = String.fromCharCode(keycode).toLowerCase(); -
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.oisv.com In PDF document text
- http://www.dynamicpad.org/In PDF document text
- http://www.rudenko.com/In PDF document text
- http://www.rudenko.com/robosoft/upgrade_prog.htmlIn PDF document text
- http://www.rudenko.com/sites/In PDF document text
- http://www.asp-shareware.org/padIn PDF document text
- http://www.wingsofdarkness.net/php/index.phpIn PDF document text
- http://www.BoltBait.comIn PDF document text
- http://www.dmashton.co.uk/In PDF document text
- http://www.xdp.it/cximage.htmIn PDF document text
- http://www.icsharpcode.net/OpenSource/SharpZipLib/Default.aspxIn PDF document text
- http://www.sjbrown.co.uk/?code=squishIn PDF document text
- http://www.pinvoke.comIn PDF document text
- http://www.oxygen-icons.org/In PDF document text
- http://www.everaldo.com/crystal/In PDF document text
- http://www.huddletogether.comIn PDF document text
- http://huddletogether.com/projects/lightbox/In PDF document text
- http://www.macecraft.com/share/lightbox/loading.gifIn PDF document text
- http://www.faqts.com/knowledge_base/view.phtml/aid/1602//functionIn PDF document text
- http://simon.incutio.com///functionIn PDF document text
- http://www.macecraft.com/images/images-2/arrow.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/header.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/textfield_bg.gifIn PDF document text
- http://www.macecraft.com/images/images-2/tabBgNew.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/user-rating-caption.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/user-rating-body.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/commonbox1-background.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/commonbox1-caption.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/commonbox1-body.pngIn PDF document text
- http://www.macecraft.com/images/images-2/commonbox1-foot.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/button1.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/list-icon.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/commonbox2-body.jpgIn PDF document text
- http://www.macecraft.com/ver2/images/emailbox.jpgIn PDF document text
- http://www.macecraft.com/ver2/images/table_heading.jpgIn PDF document text
- http://www.macecraft.com/images/images-2/tabBgNew2.jpgIn PDF document text
- http://illusionaryz.deviantart.com}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
- http://www.BoltBait.com}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
- http://www.dmashton.co.uk/}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
- http://www.xdp.it/cximage.htm}}}\f0\fs18In extracted file (embedded_pdf_00166000.exe)
- http://www.icsharpcode.net/OpenSource/SharpZipLib/Default.aspx}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
- http://www.sjbrown.co.uk/?code=squish}}}\b\f0\fs18In extracted file (embedded_pdf_00166000.exe)
- http://www.pinvoke.com}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
- http://www.oxygen-icons.org/}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
- http://www.everaldo.com/crystal/}}}\f2\fs18\parIn extracted file (embedded_pdf_00166000.exe)
- http://www.faqts.com/knowledge_base/view.phtml/aid/1602In extracted file (embedded_pdf_00166000.exe)
- http://simon.incutio.com/In extracted file (embedded_pdf_00166000.exe)
- http://www.monotype.comhttp://www.monotype.com/html/type/license.htmlIn extracted file (font_00_sfnt_off00117a3e.bin)
- http://mydomain.com/dp/In PDF document text
- http://illusionaryz.deviantart.comIn PDF document text
+10 more URL(s)
🗂 Part of campaign:
buchung.pl
5 samples
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_pdf_00166000.exe |
embedded-pe | PDF raw PDF bytes PE payload at offset 0x166000 | 1284096 bytes |
SHA-256: 16136261e629838a327ad9777a40f35e1d5f277269937b1fec0e2dd83ed22e18 |
|||
|
Detection
ClamAV:
Win.Trojan.Krile-4
Obfuscation or payload:
likely
actual_type=PE; declared_or_context_type=PDF; filename=embedded_pdf_00166000.exe; kind=embedded-pe Carved artifact contains 2 shell/COM execution token(s).
|
|||
font_00_sfnt_off00117a3e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x117A3E | 34992 bytes |
SHA-256: aa200be6d4324263de453df695a258f4a0f764b51a48d1d42ef82a5d1d1e26b2 |
|||
font_01_sfnt_off0011cb1a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11CB1A | 1164 bytes |
SHA-256: bb467a1c790e72582b417d7fd79ca9f536e5067f5fa6fdc7f620c2d339792a1b |
|||
font_02_sfnt_off0011d04e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11D04E | 37820 bytes |
SHA-256: 33a060a94d55f5f175c301c82e07d1b78ade08759c89e0b7cedb9c353bc6f860 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.