Malicious PDF — malware analysis report

Static analysis result for SHA-256 251457517b050efe…

MALICIOUS

PDF

604.3 KB Created: 2011-02-24 09:42:19 +11:00 Authoring application: Adobe LiveCycle Designer 8.0 First seen: 2026-05-08
MD5: 724b38bc8d411a3fa1db5b880f8e67b6 SHA-1: 44a719d896bb2fc9d0d55e2e8d4afa9043e30df6 SHA-256: 251457517b050efeb5efd713fa59203ae18e4c93c4dcc106783717b7aee03cac
224 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF document utilizes XFA forms and embedded JavaScript, triggering multiple high-severity heuristics related to PDF exploits and malicious JavaScript. The document body contains text related to payment, invoices, and bank details, indicating a lure for financial information or to prompt the user to update their software. The JavaScript code attempts to redirect the user to 'http://cgi.adobe.com/special/acrobat/update' which is likely a social engineering tactic to download a malicious payload or exploit.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9583

Heuristics 12

  • TrueType bitmap font + active content — CVE-2023-26369 related high CVE related PDF_CVE_2023_26369_RELATED
    PDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded script payload in PDF stream info PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ocsp.verisign.com0�� In PDF document text
    • http://www.monotype.comHowardIn PDF document text
    • http://ocsp.verisign.com0In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://ns.adobe.com/tiff/1.0/In PDF document text
    • http://ns.adobe.com/exif/1.0/In PDF document text
    • http://ns.adobe.com/photoshop/1.0/In PDF document text
    • http://www.iec.chIn PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.5/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.1/Referenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In PDF document text
    • http://www.xfa.org/schema/xci/1.0/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.1/In PDF document text
    • http://ns.adobe.com/xtd/In PDF document text
    • http://ns.adobe.com/xfdf/In PDF document text
    • https://www.verisign.com/rpaIn PDF document text
    • https://www.verisign.com/rpa03In PDF document text
    • http://crl.verisign.com/pca3.1.1.crl0In PDF document text
    • http://ocsp.verisign.com/ocsp/status0In PDF document text
    • https://www.verisign.com/rpa0In PDF document text
    • http://crl.verisign.com/Class3CodeSigningCA2001.crl0��In PDF document text
    • https://www.verisign.com/repository/CPS0KIn PDF document text
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlIn PDF document text
    • https://www.verisign.com/repository/RPA0In PDF document text
    • https://www.verisign.com/repository/CPS��In PDF document text
    • https://www.verisign.comIn PDF document text
    • https://www.verisign.com/repository/verisignlogo.gif0�In PDF document text
    • https://www.verisign.com/CPSIn PDF document text
    • https://www.verisign.com/repository/CPSIn PDF document text
    • http://www.microsoft.com/truetype/0In PDF document text
    • http://www.monotype.com/html/mtname/ms_couriernew.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
    • http://crl.verisign.com/tss-ca.crl0In PDF document text
    • https://www.verisign.com/rpa01In PDF document text
    • http://crl.verisign.com/pca3.crl0In PDF document text
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DIn PDF document text
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0In PDF document text

Extracted artifacts 17

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0048.bin pdf-embedded-file PDF EmbeddedFile object 48 at offset 0x8D45B 85 bytes
SHA-256: c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
embedded_file_obj0049.bin pdf-embedded-file PDF EmbeddedFile object 49 at offset 0x8D50F 3494 bytes
SHA-256: 8aaf9c7ae09c55a5c59a49dacf07cb47fa01df81181f2eec65bb4a827a220778
embedded_file_obj0050.bin pdf-embedded-file PDF EmbeddedFile object 50 at offset 0x8DA3D 106426 bytes
SHA-256: 71c8c86bb7f45a8f656ccde7300cd717a6e3954169f7006f29655482ec4b940d
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 long base64-like blob(s).
embedded_file_obj0051.bin pdf-embedded-file PDF EmbeddedFile object 51 at offset 0x93BB8 1477 bytes
SHA-256: 09cafa7db2c4d1a66eec54523fad5aa408c6d5f720ecfc0072a631b505827180
embedded_file_obj0052.bin pdf-embedded-file PDF EmbeddedFile object 52 at offset 0x93DF4 2400 bytes
SHA-256: 838c18047c9d1742a502d2eeb49be157ff9801bb3cdd87d0c2fbb39ea189bc13
embedded_file_obj0053.bin pdf-embedded-file PDF EmbeddedFile object 53 at offset 0x940D1 214 bytes
SHA-256: 7e915b5dd2e321929666a7b64c038b67678092d6e43a4a70683521856a4d5128
embedded_file_obj0054.bin pdf-embedded-file PDF EmbeddedFile object 54 at offset 0x941CC 799 bytes
SHA-256: b094789276d6faad13f4781393b7e19185bc45b43faea5434af6c491603440c4
embedded_file_obj0055.bin pdf-embedded-file PDF EmbeddedFile object 55 at offset 0x943DC 110 bytes
SHA-256: b1b296d371e691ae903fc90e2f3bd69eeac3730137d7c7f5d9379aed02cb51d6
javascript_obj0259_000.js pdf-javascript-stream PDF /JS object 259 at offset 0xF3C 1535 bytes
SHA-256: 04ceb4c2218e7db19a6e007ca4ce846f92c17fff5eaf3a611e71bbd7a5726917
Preview script
First 1,000 lines of the extracted script
if (typeof(xfa_installed) == "undefined" || typeof(xfa_version) == "undefined" || xfa_version < 2.1)
{
   if (app.viewerType == "Reader")
   {
      if (ADBE.Reader_Value_Asked != true)
      {
         if (app.viewerVersion < 6.0)
         {
            if (app.alert(ADBE.Viewer_Form_string_Reader_5x, 1, 1) == 1)
               this.getURL(ADBE.Reader_Value_New_Version_URL + ADBE.SYSINFO, false);
            ADBE.Reader_Value_Asked = true;
         }
         else if (app.viewerVersion < 7.0)
         {
            if (app.alert(ADBE.Viewer_Form_string_Reader_601, 1, 1) == 1)
               app.findComponent({cType:"App", cName:"Reader7", cDesc: ADBE.Viewer_string_Update_Reader_Desc});
            ADBE.Reader_Value_Asked = true;
         }
         else
         {
            if (app.alert(ADBE.Viewer_Form_string_Reader_6_7x, 1, 1) == 1)
               app.findComponent({cType:"Plugin", cName:"XFA", cDesc: ADBE.Viewer_string_Update_Reader_Desc});
            ADBE.Reader_Value_Asked = true;
         }
      }
   }
   else
   {
      if (ADBE.Viewer_Value_Asked != true)
      {
         if (app.viewerVersion < 7.0)
            app.response({cQuestion: ADBE.Viewer_Form_string_Viewer_Older, cDefault: ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, cTitle: ADBE.Viewer_string_Title});
         else if (app.alert(ADBE.Viewer_Form_string_Viewer_7x, 1, 1) == 1)
            app.findComponent({cType:"Plugin", cName:"XFA", cDesc: ADBE.Viewer_string_Update_Desc});
         ADBE.Viewer_Value_Asked = true;
      }
   }
}
javascript_obj0260_001.js pdf-javascript-stream PDF /JS object 260 at offset 0x1128 870 bytes
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
Preview script
First 1,000 lines of the extracted script
if (typeof(ADBE.Reader_Value_Asked) == "undefined")
   ADBE.Reader_Value_Asked = false;
if (typeof(ADBE.Viewer_Value_Asked) == "undefined")
   ADBE.Viewer_Value_Asked = false;
if (typeof(ADBE.Reader_Need_Version) == "undefined" || ADBE.Reader_Need_Version < 7.0)
{
   ADBE.Reader_Need_Version = 7.0;
   ADBE.Reader_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&w=" + "XFA1_6";
}
if (typeof(ADBE.Viewer_Need_Version) == "undefined" || ADBE.Viewer_Need_Version < 7.0)
{
   ADBE.Viewer_Need_Version = 7.0;
   ADBE.Viewer_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&w=" + "XFA1_6";
}
javascript_obj0261_002.js pdf-javascript-stream PDF /JS object 261 at offset 0x1283 2798 bytes
SHA-256: 922f7942d25f53e6e6eedc1b3a95c47a757faab3be4838fa02db0dbea2c4dbcc
Preview script
First 1,000 lines of the extracted script
if (typeof(this.ADBE) == "undefined")
   this.ADBE = new Object();
ADBE.LANGUAGE = "ENU";
ADBE.Viewer_string_Title = "Adobe Acrobat";
ADBE.Viewer_string_Update_Desc = "Adobe Interactive Forms Update";
ADBE.Viewer_string_Update_Reader_Desc = "Adobe Reader 7.0.5";
ADBE.Reader_string_Need_New_Version_Msg = "This PDF file requires a newer version of Adobe Reader. Press OK to download the latest version or see your system administrator.";
ADBE.Viewer_Form_string_Reader_601 = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator.";
ADBE.Viewer_Form_string_Reader_Older = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK for online download information or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_601 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_60 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. For more information please copy the following URL (CTRL+C on Win, Command-C on Mac) and paste into your browser or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_Older = "This PDF requires a newer version of Acrobat. Copy this URL and paste into your browser or see your sys admin.";
ADBE.Viewer_Form_string_Reader_5x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will open your browser to a web page where you can obtain the latest version.";
ADBE.Viewer_Form_string_Reader_6_7x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version.";
ADBE.Viewer_Form_string_Viewer_7x = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version.";
stream_024_off00025a11.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x25A11 35435 bytes
SHA-256: 61f62c6ab38f53bc4792813a8141798d141790e3561c10d8686b5f7bf30bec6f
stream_028_off0005bf09.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5BF09 312899 bytes
SHA-256: c70024768d2c352e2ed466198a3c3e8d1c3c4a3ec9cd2bbeec045e5cba81c5c0
font_00_cff_off000098eb.bin pdf-font-stream PDF embedded font (cff) at offset 0x98EB 5812 bytes
SHA-256: 5e07d4564a1a7f2bf3d82e15ceb243eeee4c0d35a3f67572718a6da44bca59fc
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.44, consistent with packed or encrypted content.
font_01_cff_off0000ae7c.bin pdf-font-stream PDF embedded font (cff) at offset 0xAE7C 3678 bytes
SHA-256: 9b795ac31de8570beab34d0ad10ba066b37c342eedec45257c5b8aeb2cc293da
font_02_cff_off0000bbe5.bin pdf-font-stream PDF embedded font (cff) at offset 0xBBE5 3689 bytes
SHA-256: daceb8a63a95e64fa7fab4a2f6a90d6cb2143066732ee6c35cee38a9921efb8b
font_03_sfnt_off000145f6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x145F6 94875 bytes
SHA-256: 058d11642e857508126df5662db2c7af4bdc1892e73eea6fc33f2605a1fc3c20