Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe156310e5da881f…

MALICIOUS

PDF

17.73 MB First seen: 2026-05-08
MD5: 560f15b3ce797f617a37a60112b27bed SHA-1: 9c9de0a4300a7843b0ae783c320ad9261e70ec81 SHA-256: fe156310e5da881fc721c4478856757efa3bfef8b82f48f89bacc104a006f733
64 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file contains embedded JavaScript and exhibits characteristics indicative of the CVE-2010-0188 exploit, specifically related to CCITTFaxDecode and XFA. The high number of streams suggests obfuscation or heap spraying techniques. The embedded JavaScript is likely responsible for triggering the exploit and executing a malicious payload.

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 4

  • CCITTFaxDecode + TIFF/XFA exploit prep — LibTIFF CVE-family indicator high CVE related PDF_CCITT_CVE_2010_0188_RELATED
    PDF uses /CCITTFaxDecode together with TIFF/XFA exploit-preparation markers such as rawValue image-field assignment, TIFF data, or heap-spray JavaScript. This matches the delivery pattern for Adobe Reader LibTIFF/CCITTFax parser exploit families, including CVE-2010-0188, but does not prove the exact malformed TIFF primitive.
  • Unusually high stream count medium PDF_MANY_STREAMS
    PDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.crest-approved.org In PDF document text
    • http://www.tigerscheme.orgIn PDF document text
    • http://www.thecyberscheme.co.ukIn PDF document text
    • http://www.pentest-standard.orgIn PDF document text
    • http://pure.iiasa.ac.at/10111/In PDF document text
    • http://cnnmon.ie/2aNyP9eIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/tiff/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/photoshop/1.0/In PDF document text
    • http://ns.adobe.com/exif/1.0/In PDF document text
    • http://oreilly.com/safariIn PDF document text
    • http://oreilly.com/catalog/errata.csp?isbn=9781491910955In PDF document text
    • http://bit.ly/2aDDbfKIn PDF document text
    • http://bit.ly/2bfCcGHIn PDF document text
    • http://bit.ly/2bfCHAdIn PDF document text
    • http://bit.ly/2bfCc9lIn PDF document text
    • http://bit.ly/2axdfSRIn PDF document text
    • http://bit.ly/2bfCAEXIn PDF document text
    • http://bit.ly/2bfCI7jIn PDF document text
    • https://youtu.be/M6qoJNLIoJIIn PDF document text
    • http://www.ietf.org/rfc.htmlIn PDF document text
    • https://cve.mitre.orgIn PDF document text
    • http://bit.ly/2bfCqgRIn PDF document text
    • http://bit.ly/2e5BuIPIn PDF document text
    • http://bit.ly/2bfCGfUIn PDF document text
    • http://examples.oreilly.com/networksa/tools/In PDF document text
    • http://examples.oreilly.com/9780596006112/tools/In PDF document text
    • http://www.oreilly.com/safariIn PDF document text
    • http://bit.ly/network-security-assessment-3eIn PDF document text
    • http://www.oreilly.comIn PDF document text
    • http://bit.ly/2aNyLq1In PDF document text
    • http://bit.ly/2aNyJhWIn PDF document text
    • http://fortune.com/In PDF document text
    • http://bit.ly/2aNyTpjIn PDF document text
    • http://reut.rs/2aNzqHUIn PDF document text
    • http://bit.ly/2aNyZxaIn PDF document text
    • http://bit.ly/2aNz3wUIn PDF document text
    • http://bit.ly/2aNz83GIn PDF document text
    • http://bit.ly/2aNz83CIn PDF document text
    • http://bit.ly/2aNzKpZIn PDF document text
    • http://bit.ly/2aNzxTPIn PDF document text
    • http://examples.oreilly.com/networksa/tools/google-xxe.pdfIn PDF document text
    • http://www.iec.chIn PDF document text

Extracted artifacts 12

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objstm_16769_00.bin pdf-objstm-decoded PDF /ObjStm 16769 0 obj (inflated) 21607 bytes
SHA-256: fff3b4fe963565b189b5b6906bb4ea4434237046a0f3f5d9e2a8aa23f1243877
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 8 long base64-like blob(s).
objstm_16815_00.bin pdf-objstm-decoded PDF /ObjStm 16815 0 obj (inflated) 19856 bytes
SHA-256: 75230c4a463d5ae453c798ffc6ece7ab51da618c134d237c6df81b4e5c576e4e
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 long base64-like blob(s).
objstm_16816_00.bin pdf-objstm-decoded PDF /ObjStm 16816 0 obj (inflated) 23435 bytes
SHA-256: 382f53399b35652f0b4f7a1e7ce812053bef5160e2932a967820d18a28878d08
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 23 long base64-like blob(s).
objstm_16817_00.bin pdf-objstm-decoded PDF /ObjStm 16817 0 obj (inflated) 23312 bytes
SHA-256: a5a7d0aa1cdd8539eb687d838a3d09a0fa4d5fb5682cb1d4d97248cd5668f6e8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 26 long base64-like blob(s).
icc_00_off000c4c95.icc pdf-icc-profile PDF ICC profile at offset 0xC4C95 3144 bytes
SHA-256: 3f6d674174f3804eb0dabdac90ae17486e898c5063a66f861c116ea033da8301
icc_01_off0022da81.icc pdf-icc-profile PDF ICC profile at offset 0x22DA81 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
icc_02_off010f94a9.icc pdf-icc-profile PDF ICC profile at offset 0x10F94A9 557168 bytes
SHA-256: 4855b8fabb96bdc6495d45d089bb8c8efb1ae18389e0dc9e75a5f701a9c0b662
font_00_cff_off0118edc7.bin pdf-font-stream PDF embedded font (cff) at offset 0x118EDC7 1014 bytes
SHA-256: 98217069ea6f8339e3bda5f1a09f1b81e796fbe14d5d15f83749324d81494ef8
font_01_cff_off0118f212.bin pdf-font-stream PDF embedded font (cff) at offset 0x118F212 2797 bytes
SHA-256: 05ec1e8e79809cd88aa55b1ddf72913342c3dbc22952f7096da65de7d84168fb
font_02_cff_off0118fb13.bin pdf-font-stream PDF embedded font (cff) at offset 0x118FB13 865 bytes
SHA-256: fc0761a66e4fbcc63d92e103099e4bf6763d249579fbdfa79e00bb75a486e140
font_03_cff_off0118feb0.bin pdf-font-stream PDF embedded font (cff) at offset 0x118FEB0 864 bytes
SHA-256: 76c12ad8beeeed6ffc8edbd91d07c3f3a0a3ce35e8577192aea0e3a70478808b
font_04_cff_off01190267.bin pdf-font-stream PDF embedded font (cff) at offset 0x1190267 193128 bytes
SHA-256: 937783e48a589fb77121464393a21ad9b539c8b8b9255f94ac0c30fa2a7ce9fc
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.49, consistent with packed or encrypted content.