Malicious PDF — malware analysis report

Static analysis result for SHA-256 f739cc41575a8828…

MALICIOUS

PDF

552.2 KB Created: 2010-06-16 16:05:22 +02:00 Authoring application: Adobe InDesign CS3 (5.0) (via Acrobat Distiller 8.0.0 (Windows)) First seen: 2026-07-11
MD5: f01be12ec2452480e071b5a1e64c6664 SHA-1: e61c56a3166e5dfde48975e67e5b690044166208 SHA-256: f739cc41575a8828e99700f8b02b3c387aba44040bc542fb8921bcbed6fab275
636 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 14

  • Adobe Reader Launch action command execution critical CVE exact CVE_2010_1240
    PDF uses the Adobe Reader/Acrobat Launch action pattern associated with CVE-2010-1240: cmd.exe is invoked with attacker-controlled parameters, paired with an embedded/exported payload.
  • ClamAV: Pdf.Tool.Agent-1388586 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Tool.Agent-1388586
  • Launch action critical PDF_LAUNCH
    PDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
  • Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
    PDF stream bytes contain an embedded Windows executable with a verified PE header. Exploit chains often hide droppers inside ordinary streams rather than standard /EmbeddedFile attachments.
  • /Launch action target: cmd.exe critical PDF_LAUNCH_COMMAND
    PDF /Launch action specifies an executable target with parameters '/Q /C %HOMEDRIVE%&cd %HOMEPATH%&(if exist "Desktop\\cyber.pdf" (cd "Desktop"' — references a known-dangerous executable (cmd, PowerShell, etc.).
  • Embedded attachment masquerades: declared document, content is windows-executable critical PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
    An /EmbeddedFile attachment's declared filename extension or /Subtype MIME type contradicts the magic bytes of its decompressed content. The attachment is declared as a benign document or image but the bytes are an executable or executable-bearing archive. This is a deliberate deception used to hide droppers in PDF attachments and is a generic indicator of embed-and-drop weaponisation, independent of any specific CVE.
  • Suspicious extracted artifact critical EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • /Launch action paired with attachment-dropping JS API high PDF_LAUNCH_PLUS_DROPPER_JS
    PDF combines a /Launch action with a JavaScript API call that writes or opens an attached/external resource — the canonical shape of the CVE-2010-1240 /Launch + exportDataObject family. Benign PDFs do not pair these surfaces; the combination indicates a drop-and-execute chain regardless of the specific JS API knobs or /Launch target.
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL tcp://192.168.56.103:2005 In extracted file (cyber.pdf)
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://www.iec.chIn extracted file (icc_00_off000021d8.icc)

Extracted artifacts 19

Files carved from inside the sample during analysis.

FilenameKindSourceSize
cyber.pdf pdf-embedded-file PDF EmbeddedFile object 188 at offset 0x896F1 7680 bytes
SHA-256: 5d07935827adb9faeb0622c5699f899387c366108ea35513cc7a4f86c7bfc3c2
Detection
ClamAV: Win.Malware.Metasploit-10022275-0
Obfuscation or payload: likely
actual_type=PE; declared_or_context_type=PDF; filename=cyber.pdf; kind=pdf-embedded-file Static shellcode analysis recovered the Metasploit stager connect-back address: 192.168.56.103:2005 (reverse/x64, lab (non-routable)) Static shellcode analysis found candidate code region(s). Indicators: SC_STR_VIRTUALPROTECT, SC_PEB_ACCESS_X64 Static shellcode analysis recovered API/import strings: kernel32.dll, KERNEL32.DLL, VirtualProtect
javascript_obj0189_000.js pdf-javascript-stream PDF /JS object 189 at offset 0x89B23 54 bytes
SHA-256: 23654b62f7867854718b980faa3240d27f2f0314f36008f8de62339d4987e641
Preview script
First 1,000 lines of the extracted script
this.exportDataObject({ cName: "cyber", nLaunch: 0 });
icc_00_off000021d8.icc pdf-icc-profile PDF ICC profile at offset 0x21D8 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
font_00_cff_off00000c6e.bin pdf-font-stream PDF embedded font (cff) at offset 0xC6E 5231 bytes
SHA-256: 5fe7b085e774b62484abbe9cfd97d1244b9c958c9494029eeaed21828840b3a4
font_01_cff_off0002c8b2.bin pdf-font-stream PDF embedded font (cff) at offset 0x2C8B2 6768 bytes
SHA-256: 663c8844cc801c97cbb08e32e90b882602af4ed88457b205535264907cafef30
font_02_cff_off0002e4f1.bin pdf-font-stream PDF embedded font (cff) at offset 0x2E4F1 5814 bytes
SHA-256: 49e862b8a5ad08dd3aef340a93de9acefdd2e9b486b0423ef295936a2e8c13b3
font_03_cff_off0002fd08.bin pdf-font-stream PDF embedded font (cff) at offset 0x2FD08 357 bytes
SHA-256: 50084c271c79b3036903fb9c4e77008e98601c618b1aee61977169c4835862b6
font_04_cff_off000503d8.bin pdf-font-stream PDF embedded font (cff) at offset 0x503D8 2953 bytes
SHA-256: 5183db43720601b4cac1bb3d34e39207d79f07ba7748e1377e5c2b1c411a526f
font_05_cff_off0006c648.bin pdf-font-stream PDF embedded font (cff) at offset 0x6C648 376 bytes
SHA-256: 538d2345849c723fcfe8abeff90721e2fa5413b8199d736be37845082ebe63eb
font_06_cff_off00072aa0.bin pdf-font-stream PDF embedded font (cff) at offset 0x72AA0 4302 bytes
SHA-256: 490f128f4ccab828a522e689a9a0b1de2f8c8cdbb2706c95fe37c5685fd0f8b2
font_07_cff_off000746e0.bin pdf-font-stream PDF embedded font (cff) at offset 0x746E0 3407 bytes
SHA-256: 0562f5d2910f40d96391b524ed3295b0951db67c6e66f1fad57116e023cb50ee
font_08_cff_off000759a1.bin pdf-font-stream PDF embedded font (cff) at offset 0x759A1 6240 bytes
SHA-256: 4b03ecd6ab5e83edbd33eaf7672132bd3070b13629893f6cb81bdf26c0d91ef7
font_09_cff_off000774ed.bin pdf-font-stream PDF embedded font (cff) at offset 0x774ED 19048 bytes
SHA-256: 92961e8bda2a79925cb9d181faaec90629d528842a9e63ff5cb44a1f89b9b02d
font_10_cff_off0007b22b.bin pdf-font-stream PDF embedded font (cff) at offset 0x7B22B 4901 bytes
SHA-256: 9e1aa3d70d5ef0f578d3b656c175d15f6d2070e5f6cf7cdd27a762e1c7491ba4
font_11_cff_off0007c826.bin pdf-font-stream PDF embedded font (cff) at offset 0x7C826 363 bytes
SHA-256: 567c2bccf8e0c2e70145ded261c5ef36f3592cb87fdb6851b66e75a7aeb82a21
font_12_cff_off0007de44.bin pdf-font-stream PDF embedded font (cff) at offset 0x7DE44 380 bytes
SHA-256: 0768ef8b9f713f6c56e210e7201a97edeb224b032d506db039b04d65fa61747b
font_13_cff_off0007e425.bin pdf-font-stream PDF embedded font (cff) at offset 0x7E425 10020 bytes
SHA-256: 72348d12ca94cab10d706f2301d811220ec7998075a3fda4c096de03c4ae8657
font_14_cff_off000805ad.bin pdf-font-stream PDF embedded font (cff) at offset 0x805AD 5943 bytes
SHA-256: 7e2b31cd27f5d9fc03ee6dfe266086d4a7b9be16ba766ca31c4846579981883b
font_15_cff_off000836e7.bin pdf-font-stream PDF embedded font (cff) at offset 0x836E7 15586 bytes
SHA-256: b48400f658cc4943c87e8e1f6b290b638d2ce4da14c17813109aa74009fc0b98
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.