PDF static analysis report

Static analysis result for SHA-256 04ffb7c030ace3d1…

SUSPICIOUS

PDF

239.2 KB Created: 2009-04-19 23:32:15 UTC Authoring application: TeX (via Mac OS X 10.5.6 Quartz PDFContext) First seen: 2026-05-08
MD5: 95eb70934c086a0f3c57f8b8f110eb9c SHA-1: eb5a092458d50ad1119ca0ef10e416db24235e9b SHA-256: 04ffb7c030ace3d15f3ba2b5b790d017a9e2529a58159e1e685f66b882840810
42 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment

The PDF contains embedded JavaScript, indicated by the 'PDF_EMBEDDED_SCRIPT_PAYLOAD' heuristic and the presence of a '.js' file among extracted artifacts. This script is likely designed to download and execute a secondary payload from a suspicious URL found in the extracted data. The document body is heavily obfuscated and unreadable, providing no direct clues to its intent beyond the technical indicators.

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 3

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.kjwd.ru/js.js In PDF document text
    • http://wepawet.csIn PDF document text
    • http://www.honeynet.org/papers/mwsIn PDF document text
    • https://projects.honeynet.org/capture-hpcIn PDF document text
    • http://wepawet.cs.ucsb.edu)]TJ/F56In PDF document text
    • http://wepawet.cs.ucsb.eduIn PDF document text
    • http://cve.mitre.org/In PDF document text
    • http://www.mozilla.org/rhino/In PDF document text
    • http://code.google.com/p/spybyeIn PDF document text
    • http://isc.sans.org/diary.html?storyid=6739In PDF document text
    • http://www.clamav.net/In PDF document text
    • http://carnal0wnage.blogspot.com/2009/04/In PDF document text
    • http://www.secureworks.com/research/tools/In PDF document text
    • http://www.edup.tudelft.nl/In PDF document text
    • http://htmlunit.sourceforge.net/In PDF document text
    • http://www.spamcop.net/In PDF document text
    • http://www.theregister.co.uk/2008/04/25/mass_In PDF document text
    • http://www.theregister.co.uk/2008/09/16/In PDF document text
    • http://www.theregister.co.uk/2010/01/15/ie_In PDF document text
    • http://code.google.com/apis/safebrowsing/In PDF document text
    • http://pfaedit.sf.net/In PDF document text

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off000013fd.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x13FD 17889 bytes
SHA-256: 8b25f11cb863a1c282e401eff0bbdb8581d9f3615e01dc22cdcd7176f582c145
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 shell/COM execution token(s).
stream_019_off00025baf.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x25BAF 17222 bytes
SHA-256: f948491e0a7cbc0daaae387d1e83e9b36a54c0346d16b133f0536ad6d8c7a721
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
stream_023_off0003189b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3189B 21001 bytes
SHA-256: efdf1fae43b5201061838f74dddd0cad8b9ebfa6cf02fe6779baae5876c337f8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
icc_00_off0000e4a1.icc pdf-icc-profile PDF ICC profile at offset 0xE4A1 1296 bytes
SHA-256: 94722fe267764797f8887379cc0d355f5118beb3d186e087bfbd9e1a3f2d3f49
icc_01_off0000e7c8.icc pdf-icc-profile PDF ICC profile at offset 0xE7C8 1456 bytes
SHA-256: 2a18161bb96fd584d19e737ce294732789e0e8e6ae8c8e4e5f09f1b138232a63
font_00_sfnt_off0000ed4f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED4F 15780 bytes
SHA-256: 99d0de9664d085c75a951ff59e91eacf8a132a975cf483aa975f77ee67342b28
font_01_sfnt_off00020752.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x20752 14344 bytes
SHA-256: 410716127de6c4963757aa5c4c4f4a5b4d2cb4b9581f068439028de2d60c2451
font_03_type1_off00029e5e.bin pdf-font-stream PDF embedded font (type1) at offset 0x29E5E 7985 bytes
SHA-256: 873445e2063a5fa4446eacfeb2c63fc4a36d92086f0ae8d63a3312251b755bb2
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.80, consistent with packed or encrypted content.
font_04_type1_off0002bc0d.bin pdf-font-stream PDF embedded font (type1) at offset 0x2BC0D 7085 bytes
SHA-256: c9145a0c4b2df139823105a635b20d43cb41234e9af5b0dd9b16793d7a1d9ee2
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.86, consistent with packed or encrypted content.
font_05_type1_off0002d7de.bin pdf-font-stream PDF embedded font (type1) at offset 0x2D7DE 16823 bytes
SHA-256: 915312615d1303a832fab3148f9a7fff47d75d8c24ac1e16c9ebb2a50a0ea9f5
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
font_07_type1_off00036a4a.bin pdf-font-stream PDF embedded font (type1) at offset 0x36A4A 17183 bytes
SHA-256: 866feb7f4a33302f6375c86fe1af85f9bbceee09ae1574f41f679ff5f8a38ba6
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.