MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious File
The PDF contains embedded JavaScript and embedded files, with one embedded PDF child exhibiting suspicious static findings. A high-severity heuristic indicates a 'Browser extension / update installation lure,' suggesting social engineering to prompt the user to install a plugin or update. This is a common tactic for credential theft or malware delivery. No scripts were directly extracted or deobfuscated to provide further detail on payload execution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9405
Heuristics 10
-
Embedded PDF child has suspicious static findings high PDF_EMBEDDED_CHILD_STATIC_TRIAGEPDF contains an embedded PDF stream whose extracted child matches suspicious or malicious PDF heuristics. Wrapper PDFs are commonly used to hide the actual exploit or lure payload from scanners that do not recursively inspect attachments.
-
Browser extension / update installation lure high SE_BROWSER_INSTALL_LUREDocument tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.pmi.org/PDF/OPM3Handbook.pdf PDF link annotation
- http://www.pmi.org/PDF/OPM3Handbook.pdf)/S/URIIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
- http://ns.adobe.com/xdp/In PDF document text
- http://www.xfa.org/schema/xci/1.0/In PDF document text
- http://www.xfa.org/schema/xfa-template/2.5/In PDF document text
- http://www.xfa.org/schema/xfa-template/2.1/In PDF document text
- http://www.w3.org/1999/xhtmlIn PDF document text
- http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
- http://www.xfa.org/schema/xfa-template/2.2/In PDF document text
- http://ns.adobe.com/xtd/In PDF document text
- http://www.xfa.org/schema/xfa-locale-set/2.1/In PDF document text
- http://ns.adobe.com/xfdf/In PDF document text
- http://www.iec.chIn PDF document text
Extracted artifacts 21
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0007.bin |
pdf-embedded-file | PDF EmbeddedFile object 7 at offset 0x10402 | 85 bytes |
SHA-256: c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb |
|||
embedded_file_obj0008.bin |
pdf-embedded-file | PDF EmbeddedFile object 8 at offset 0x104B5 | 3255 bytes |
SHA-256: 8313b0b6cf4ccf8d8f4d08d8239c0eecc8b346f8d0a2ac3b941d0e3fce5023b7 |
|||
embedded_file_obj0009.bin |
pdf-embedded-file | PDF EmbeddedFile object 9 at offset 0x10966 | 25389 bytes |
SHA-256: f0c163576d8710e5ef80b0ed22cbd2bb17662f5c9fb5d862a63ed35b74c4ddc0 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 5 long base64-like blob(s).
|
|||
embedded_file_obj0010.bin |
pdf-embedded-file | PDF EmbeddedFile object 10 at offset 0x11D04 | 214 bytes |
SHA-256: 7e915b5dd2e321929666a7b64c038b67678092d6e43a4a70683521856a4d5128 |
|||
embedded_file_obj0011.bin |
pdf-embedded-file | PDF EmbeddedFile object 11 at offset 0x11DFF | 2423 bytes |
SHA-256: 2d58413fda1ff20c994606823bf49e41194612c0137b6315e50fa7bdc01f1e09 |
|||
embedded_file_obj0012.bin |
pdf-embedded-file | PDF EmbeddedFile object 12 at offset 0x120E1 | 2087 bytes |
SHA-256: 4707b0863d526baff0d4c0e4c941064d095f409fb10cf33dc743c077abdc678b |
|||
embedded_file_obj0013.bin |
pdf-embedded-file | PDF EmbeddedFile object 13 at offset 0x1223F | 799 bytes |
SHA-256: b9892eb3317eb6d9f6cdb9a91aa82288daec7e6f91a41505b1799a8d10285cbe |
|||
embedded_file_obj0014.bin |
pdf-embedded-file | PDF EmbeddedFile object 14 at offset 0x1244D | 110 bytes |
SHA-256: b1b296d371e691ae903fc90e2f3bd69eeac3730137d7c7f5d9379aed02cb51d6 |
|||
javascript_obj0149_000.js |
pdf-javascript-stream | PDF /JS object 149 at offset 0xBF9 | 1535 bytes |
SHA-256: 04ceb4c2218e7db19a6e007ca4ce846f92c17fff5eaf3a611e71bbd7a5726917 |
|||
Preview scriptFirst 1,000 lines of the extracted script
if (typeof(xfa_installed) == "undefined" || typeof(xfa_version) == "undefined" || xfa_version < 2.1)
{
if (app.viewerType == "Reader")
{
if (ADBE.Reader_Value_Asked != true)
{
if (app.viewerVersion < 6.0)
{
if (app.alert(ADBE.Viewer_Form_string_Reader_5x, 1, 1) == 1)
this.getURL(ADBE.Reader_Value_New_Version_URL + ADBE.SYSINFO, false);
ADBE.Reader_Value_Asked = true;
}
else if (app.viewerVersion < 7.0)
{
if (app.alert(ADBE.Viewer_Form_string_Reader_601, 1, 1) == 1)
app.findComponent({cType:"App", cName:"Reader7", cDesc: ADBE.Viewer_string_Update_Reader_Desc});
ADBE.Reader_Value_Asked = true;
}
else
{
if (app.alert(ADBE.Viewer_Form_string_Reader_6_7x, 1, 1) == 1)
app.findComponent({cType:"Plugin", cName:"XFA", cDesc: ADBE.Viewer_string_Update_Reader_Desc});
ADBE.Reader_Value_Asked = true;
}
}
}
else
{
if (ADBE.Viewer_Value_Asked != true)
{
if (app.viewerVersion < 7.0)
app.response({cQuestion: ADBE.Viewer_Form_string_Viewer_Older, cDefault: ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, cTitle: ADBE.Viewer_string_Title});
else if (app.alert(ADBE.Viewer_Form_string_Viewer_7x, 1, 1) == 1)
app.findComponent({cType:"Plugin", cName:"XFA", cDesc: ADBE.Viewer_string_Update_Desc});
ADBE.Viewer_Value_Asked = true;
}
}
}
|
|||
javascript_obj0150_001.js |
pdf-javascript-stream | PDF /JS object 150 at offset 0xDE5 | 870 bytes |
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb |
|||
Preview scriptFirst 1,000 lines of the extracted script
if (typeof(ADBE.Reader_Value_Asked) == "undefined")
ADBE.Reader_Value_Asked = false;
if (typeof(ADBE.Viewer_Value_Asked) == "undefined")
ADBE.Viewer_Value_Asked = false;
if (typeof(ADBE.Reader_Need_Version) == "undefined" || ADBE.Reader_Need_Version < 7.0)
{
ADBE.Reader_Need_Version = 7.0;
ADBE.Reader_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&w=" + "XFA1_6";
}
if (typeof(ADBE.Viewer_Need_Version) == "undefined" || ADBE.Viewer_Need_Version < 7.0)
{
ADBE.Viewer_Need_Version = 7.0;
ADBE.Viewer_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&w=" + "XFA1_6";
}
|
|||
javascript_obj0151_002.js |
pdf-javascript-stream | PDF /JS object 151 at offset 0xF40 | 2798 bytes |
SHA-256: 922f7942d25f53e6e6eedc1b3a95c47a757faab3be4838fa02db0dbea2c4dbcc |
|||
Preview scriptFirst 1,000 lines of the extracted script
if (typeof(this.ADBE) == "undefined") this.ADBE = new Object(); ADBE.LANGUAGE = "ENU"; ADBE.Viewer_string_Title = "Adobe Acrobat"; ADBE.Viewer_string_Update_Desc = "Adobe Interactive Forms Update"; ADBE.Viewer_string_Update_Reader_Desc = "Adobe Reader 7.0.5"; ADBE.Reader_string_Need_New_Version_Msg = "This PDF file requires a newer version of Adobe Reader. Press OK to download the latest version or see your system administrator."; ADBE.Viewer_Form_string_Reader_601 = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator."; ADBE.Viewer_Form_string_Reader_Older = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK for online download information or see your system administrator."; ADBE.Viewer_Form_string_Viewer_601 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator."; ADBE.Viewer_Form_string_Viewer_60 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. For more information please copy the following URL (CTRL+C on Win, Command-C on Mac) and paste into your browser or see your system administrator."; ADBE.Viewer_Form_string_Viewer_Older = "This PDF requires a newer version of Acrobat. Copy this URL and paste into your browser or see your sys admin."; ADBE.Viewer_Form_string_Reader_5x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will open your browser to a web page where you can obtain the latest version."; ADBE.Viewer_Form_string_Reader_6_7x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version."; ADBE.Viewer_Form_string_Viewer_7x = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version."; |
|||
font_00_cff_off0000ef3f.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xEF3F | 2402 bytes |
SHA-256: a9c85193681ee48fca472bff404852ba0a28d64c103b8dbc31ed7cbf01f3712c |
|||
font_01_cff_off0000fac1.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xFAC1 | 858 bytes |
SHA-256: 9de92a37c091d12910ec4a37a3ea8eb990d50fd05fc0d8e1720ea93e28f8e0e3 |
|||
2._Contact_Information.pdf |
pdf-embedded-file | PDF EmbeddedFile object 3 at offset 0x112D5 | 83366 bytes |
SHA-256: 560244dc21b03aa9de39cdc7074b877578fe82a825cd2360e67e3dc49195e11d |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 20 long base64-like blob(s).
|
|||
3._Education_and_PM_Experience.pdf |
pdf-embedded-file | PDF EmbeddedFile object 4 at offset 0x1F959 | 54232 bytes |
SHA-256: af2271596ba07e2c831145234eb9d2d48a743e74e920c6c31a126bc503c875ca |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
4._Assessing_and_Consulting_Experience.pdf |
pdf-embedded-file | PDF EmbeddedFile object 5 at offset 0x385DF | 52042 bytes |
SHA-256: d82584ddbf849d8c63f7fb7c926b82210b3165bb88dffeb9c789a85dc8213b98 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
5._OPM3_Knowledge_and_Experience.pdf |
pdf-embedded-file | PDF EmbeddedFile object 6 at offset 0x50B44 | 111832 bytes |
SHA-256: 4dd7414ed83bbb7e23019ed86b8c72f54ccdcc22859c4d2fcbd2abe765339fd8 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
7._Fax_Covers_Sheet.pdf |
pdf-embedded-file | PDF EmbeddedFile object 8 at offset 0x8CEC1 | 72592 bytes |
SHA-256: bd67ce011c52a3d0b799ce7ce8fc2c073205ce761423bf09b82770212f88174d |
|||
javascript_obj0038_000.js |
pdf-javascript-stream | PDF /JS object 38 at offset 0x6AD | 1379 bytes |
SHA-256: 736c69993d4cd953676f5971bd943955c344f3001c77f281afd5d8df5a456b51 |
|||
Preview scriptFirst 1,000 lines of the extracted script
var v = app.viewerVersion;
if (v < 7)
{
var n = 0;
if (this.dataObjects != null)
n = this.dataObjects.length;
if (v >= 5 && v < 6 && n > 0 && (app.viewerVariation == "Full" || app.viewerVariation == "Fill-In"))
{
if (this.external)
app.alert("This document has file attachments. To view the attachments, click the Save button to save a copy of the document, open the copy in Acrobat, and use the File > Document Properties > Embedded Data Objects menu.", 3, 0);
else
app.alert("This document has file attachments. Use the File > Document Properties > Embedded Data Objects menu to view the attachments.", 3, 0);
}
else if (v >= 6 && v < 7)
{
if (n == 0)
{
var np = this.numPages;
syncAnnotScan();
for (var p = 0; p < np && n == 0; ++p)
{
var annots = this.getAnnots(p);
if (annots != null)
{
for (var i = 0; i < annots.length; ++i)
{
if (annots[i].type == "FileAttachment")
{
n = 1;
break;
}
}
}
}
}
if (n > 0)
{
if (this.external)
app.alert("This document has file attachments. To view the attachments, click the black triangle at the top of the document window's vertical scrollbar and choose File Attachments.", 3, 0);
else
app.alert("This document has file attachments. Use the Document > File Attachments menu to view the attachments.", 3, 0);
}
}
}
|
|||
stream_016_off00068c7c.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x68C7C | 64259 bytes |
SHA-256: 44a75febaaaaa07ba399ce381361ead12c453742b144277fc335d0c0e293648b |
|||
icc_00_off00002144.icc |
pdf-icc-profile | PDF ICC profile at offset 0x2144 | 3144 bytes |
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.