MALICIOUS
636
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9925
Heuristics 14
-
Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
-
ClamAV: Pdf.Tool.Agent-1388586 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Tool.Agent-1388586
-
Launch action critical PDF_LAUNCHPDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
-
Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOADPDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
-
/Launch action target: cmd.exe critical PDF_LAUNCH_COMMANDPDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\cyber.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
-
Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCHAn /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
-
Suspicious extracted artifact critical EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
/Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JSPDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
-
Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LUREDocument describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL tcp://192.168.56.103:2005 In extracted file (cyber.pdf)
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://www.iec.chIn extracted file (icc_00_off000021d8.icc)
Extracted artifacts 19
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
cyber.pdf |
pdf-embedded-file | PDF EmbeddedFile object 188 at offset 0x896F1 | 7680 bytes |
SHA-256: 5d07935827adb9faeb0622c5699f899387c366108ea35513cc7a4f86c7bfc3c2 |
|||
|
Detection
ClamAV:
Win.Malware.Metasploit-10022275-0
Obfuscation or payload:
likely
actual_type=PE; declared_or_context_type=PDF; filename=cyber.pdf; kind=pdf-embedded-file Static shellcode analysis recovered the Metasploit stager connect-back address: 192.168.56.103:2005 (reverse/x64, lab (non-routable)) Static shellcode analysis found candidate code region(s). Indicators: SC_STR_VIRTUALPROTECT, SC_PEB_ACCESS_X64 Static shellcode analysis recovered API/import strings: kernel32.dll, KERNEL32.DLL, VirtualProtect
|
|||
javascript_obj0189_000.js |
pdf-javascript-stream | PDF /JS object 189 at offset 0x89B23 | 54 bytes |
SHA-256: 23654b62f7867854718b980faa3240d27f2f0314f36008f8de62339d4987e641 |
|||
Preview scriptFirst 1,000 lines of the extracted script
this.exportDataObject({ cName: "cyber", nLaunch: 0 });
|
|||
icc_00_off000021d8.icc |
pdf-icc-profile | PDF ICC profile at offset 0x21D8 | 3144 bytes |
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
|||
font_00_cff_off00000c6e.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xC6E | 5231 bytes |
SHA-256: 5fe7b085e774b62484abbe9cfd97d1244b9c958c9494029eeaed21828840b3a4 |
|||
font_01_cff_off0002c8b2.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2C8B2 | 6768 bytes |
SHA-256: 663c8844cc801c97cbb08e32e90b882602af4ed88457b205535264907cafef30 |
|||
font_02_cff_off0002e4f1.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2E4F1 | 5814 bytes |
SHA-256: 49e862b8a5ad08dd3aef340a93de9acefdd2e9b486b0423ef295936a2e8c13b3 |
|||
font_03_cff_off0002fd08.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2FD08 | 357 bytes |
SHA-256: 50084c271c79b3036903fb9c4e77008e98601c618b1aee61977169c4835862b6 |
|||
font_04_cff_off000503d8.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x503D8 | 2953 bytes |
SHA-256: 5183db43720601b4cac1bb3d34e39207d79f07ba7748e1377e5c2b1c411a526f |
|||
font_05_cff_off0006c648.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x6C648 | 376 bytes |
SHA-256: 538d2345849c723fcfe8abeff90721e2fa5413b8199d736be37845082ebe63eb |
|||
font_06_cff_off00072aa0.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x72AA0 | 4302 bytes |
SHA-256: 490f128f4ccab828a522e689a9a0b1de2f8c8cdbb2706c95fe37c5685fd0f8b2 |
|||
font_07_cff_off000746e0.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x746E0 | 3407 bytes |
SHA-256: 0562f5d2910f40d96391b524ed3295b0951db67c6e66f1fad57116e023cb50ee |
|||
font_08_cff_off000759a1.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x759A1 | 6240 bytes |
SHA-256: 4b03ecd6ab5e83edbd33eaf7672132bd3070b13629893f6cb81bdf26c0d91ef7 |
|||
font_09_cff_off000774ed.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x774ED | 19048 bytes |
SHA-256: 92961e8bda2a79925cb9d181faaec90629d528842a9e63ff5cb44a1f89b9b02d |
|||
font_10_cff_off0007b22b.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x7B22B | 4901 bytes |
SHA-256: 9e1aa3d70d5ef0f578d3b656c175d15f6d2070e5f6cf7cdd27a762e1c7491ba4 |
|||
font_11_cff_off0007c826.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x7C826 | 363 bytes |
SHA-256: 567c2bccf8e0c2e70145ded261c5ef36f3592cb87fdb6851b66e75a7aeb82a21 |
|||
font_12_cff_off0007de44.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x7DE44 | 380 bytes |
SHA-256: 0768ef8b9f713f6c56e210e7201a97edeb224b032d506db039b04d65fa61747b |
|||
font_13_cff_off0007e425.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x7E425 | 10020 bytes |
SHA-256: 72348d12ca94cab10d706f2301d811220ec7998075a3fda4c096de03c4ae8657 |
|||
font_14_cff_off000805ad.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x805AD | 5943 bytes |
SHA-256: 7e2b31cd27f5d9fc03ee6dfe266086d4a7b9be16ba766ca31c4846579981883b |
|||
font_15_cff_off000836e7.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x836E7 | 15586 bytes |
SHA-256: b48400f658cc4943c87e8e1f6b290b638d2ce4da14c17813109aa74009fc0b98 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.