Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b36269d0ef802cf…

MALICIOUS

PDF

487.0 KB Created: bôb2J2„=C…ÝèW¿%uˆ:I 3 Authoring application: gª?` NÔzö» è0Ý}^Dq0Wً¶ First seen: 2026-05-09
MD5: e6f93e948238ae97f0d295aa5dfbbe43 SHA-1: e7f2a57366ae4b4e4939047fda33faae721baaf0 SHA-256: 2b36269d0ef802cfe5bc548f1394e152bfc888498dd8f11aafd54be066c79cdc
114 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The PDF is encrypted and contains JavaScript, a common technique to obscure malicious payloads from static analysis. The ML classifier strongly indicates maliciousness. The presence of JavaScript actions and embedded JS streams suggests the script is responsible for executing the malicious payload, likely involving obfuscation to evade detection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9773

Heuristics 8

  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.monotype.comMonotype In PDF document text
    • http://ocsp.verisign.com0In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In PDF document text
    • http://www.xfa.org/schema/xci/1.0/In PDF document text
    • http://www.xfa.org/schema/xfa-template/2.5/In PDF document text
    • http://www.w3.org/1999/xhtmlIn PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://www.xfa.org/schema/xfa-template/2.1/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.1/In PDF document text
    • http://ns.adobe.com/xtd/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xfdf/In PDF document text
    • https://www.verisign.com/rpaIn PDF document text
    • http://ocsp.verisign.com/ocsp/status0In PDF document text
    • https://www.verisign.com/rpa0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text
    • http://www.monotype.com/html/mtname/ms_timesnewroman.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
    • http://crl.verisign.com/tss-ca.crl0In PDF document text
    • https://www.verisign.com/rpa01In PDF document text
    • http://crl.verisign.com/pca3.crl0In PDF document text
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DIn PDF document text
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0In PDF document text
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlIn PDF document text

Extracted artifacts 23

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0012.bin pdf-embedded-file PDF EmbeddedFile object 12 at offset 0x1B4C 85 bytes
SHA-256: c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
embedded_file_obj0013.bin pdf-embedded-file PDF EmbeddedFile object 13 at offset 0x1C00 3465 bytes
SHA-256: 5f6682c4e7e9198a5d05648687ff19493ca7191994b1ec9b5df7cf3a026d4449
embedded_file_obj0014.bin pdf-embedded-file PDF EmbeddedFile object 14 at offset 0x2101 65866 bytes
SHA-256: 0d9536a26578d11584c165b5532455ec17be37b5ef6908f27c8e84fc21ecb1b8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0015.bin pdf-embedded-file PDF EmbeddedFile object 15 at offset 0x3C93 923 bytes
SHA-256: ff3fd0dd53a2225f3c5385255ae03ca37a1ad9992c95d48ad8641267aa82f122
embedded_file_obj0016.bin pdf-embedded-file PDF EmbeddedFile object 16 at offset 0x3D86 2423 bytes
SHA-256: 2d58413fda1ff20c994606823bf49e41194612c0137b6315e50fa7bdc01f1e09
embedded_file_obj0017.bin pdf-embedded-file PDF EmbeddedFile object 17 at offset 0x4067 214 bytes
SHA-256: ce4ce96dd60f06a9a21bfdd239fb125edfa6efb3de453e93540a9bcbb5c57ca7
embedded_file_obj0018.bin pdf-embedded-file PDF EmbeddedFile object 18 at offset 0x4166 799 bytes
SHA-256: a1804949c7522565f37ad62a8c1af7fe77121efb111a79848103752bda0904d5
embedded_file_obj0019.bin pdf-embedded-file PDF EmbeddedFile object 19 at offset 0x4373 110 bytes
SHA-256: b1b296d371e691ae903fc90e2f3bd69eeac3730137d7c7f5d9379aed02cb51d6
javascript_obj0114_000.js pdf-javascript-stream PDF /JS object 114 at offset 0x6E63B 2798 bytes
SHA-256: 922f7942d25f53e6e6eedc1b3a95c47a757faab3be4838fa02db0dbea2c4dbcc
Preview script
First 1,000 lines of the extracted script
if (typeof(this.ADBE) == "undefined")
   this.ADBE = new Object();
ADBE.LANGUAGE = "ENU";
ADBE.Viewer_string_Title = "Adobe Acrobat";
ADBE.Viewer_string_Update_Desc = "Adobe Interactive Forms Update";
ADBE.Viewer_string_Update_Reader_Desc = "Adobe Reader 7.0.5";
ADBE.Reader_string_Need_New_Version_Msg = "This PDF file requires a newer version of Adobe Reader. Press OK to download the latest version or see your system administrator.";
ADBE.Viewer_Form_string_Reader_601 = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator.";
ADBE.Viewer_Form_string_Reader_Older = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK for online download information or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_601 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_60 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. For more information please copy the following URL (CTRL+C on Win, Command-C on Mac) and paste into your browser or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_Older = "This PDF requires a newer version of Acrobat. Copy this URL and paste into your browser or see your sys admin.";
ADBE.Viewer_Form_string_Reader_5x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will open your browser to a web page where you can obtain the latest version.";
ADBE.Viewer_Form_string_Reader_6_7x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version.";
ADBE.Viewer_Form_string_Viewer_7x = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version.";
javascript_obj0115_001.js pdf-javascript-stream PDF /JS object 115 at offset 0x6E903 870 bytes
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
Preview script
First 1,000 lines of the extracted script
if (typeof(ADBE.Reader_Value_Asked) == "undefined")
   ADBE.Reader_Value_Asked = false;
if (typeof(ADBE.Viewer_Value_Asked) == "undefined")
   ADBE.Viewer_Value_Asked = false;
if (typeof(ADBE.Reader_Need_Version) == "undefined" || ADBE.Reader_Need_Version < 7.0)
{
   ADBE.Reader_Need_Version = 7.0;
   ADBE.Reader_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&w=" + "XFA1_6";
}
if (typeof(ADBE.Viewer_Need_Version) == "undefined" || ADBE.Viewer_Need_Version < 7.0)
{
   ADBE.Viewer_Need_Version = 7.0;
   ADBE.Viewer_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&w=" + "XFA1_6";
}
javascript_obj0116_002.js pdf-javascript-stream PDF /JS object 116 at offset 0x6EA5C 1535 bytes
SHA-256: 04ceb4c2218e7db19a6e007ca4ce846f92c17fff5eaf3a611e71bbd7a5726917
Preview script
First 1,000 lines of the extracted script
if (typeof(xfa_installed) == "undefined" || typeof(xfa_version) == "undefined" || xfa_version < 2.1)
{
   if (app.viewerType == "Reader")
   {
      if (ADBE.Reader_Value_Asked != true)
      {
         if (app.viewerVersion < 6.0)
         {
            if (app.alert(ADBE.Viewer_Form_string_Reader_5x, 1, 1) == 1)
               this.getURL(ADBE.Reader_Value_New_Version_URL + ADBE.SYSINFO, false);
            ADBE.Reader_Value_Asked = true;
         }
         else if (app.viewerVersion < 7.0)
         {
            if (app.alert(ADBE.Viewer_Form_string_Reader_601, 1, 1) == 1)
               app.findComponent({cType:"App", cName:"Reader7", cDesc: ADBE.Viewer_string_Update_Reader_Desc});
            ADBE.Reader_Value_Asked = true;
         }
         else
         {
            if (app.alert(ADBE.Viewer_Form_string_Reader_6_7x, 1, 1) == 1)
               app.findComponent({cType:"Plugin", cName:"XFA", cDesc: ADBE.Viewer_string_Update_Reader_Desc});
            ADBE.Reader_Value_Asked = true;
         }
      }
   }
   else
   {
      if (ADBE.Viewer_Value_Asked != true)
      {
         if (app.viewerVersion < 7.0)
            app.response({cQuestion: ADBE.Viewer_Form_string_Viewer_Older, cDefault: ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, cTitle: ADBE.Viewer_string_Title});
         else if (app.alert(ADBE.Viewer_Form_string_Viewer_7x, 1, 1) == 1)
            app.findComponent({cType:"Plugin", cName:"XFA", cDesc: ADBE.Viewer_string_Update_Desc});
         ADBE.Viewer_Value_Asked = true;
      }
   }
}
stream_020_off0003151b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3151B 409252 bytes
SHA-256: a0f5b5f69a88877ffaa1733f0e0bbf9b4b3eef82f4ff804c724870cecea228d2
font_00_sfnt_off00021a74.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x21A74 94875 bytes
SHA-256: 058d11642e857508126df5662db2c7af4bdc1892e73eea6fc33f2605a1fc3c20
font_01_cff_off00070cc2.bin pdf-font-stream PDF embedded font (cff) at offset 0x70CC2 4859 bytes
SHA-256: 898d20ac33f56c1cefed5cc29bd1855f2796de5071eea559fcde55ba0ee3f0e1
font_02_cff_off00071e73.bin pdf-font-stream PDF embedded font (cff) at offset 0x71E73 2459 bytes
SHA-256: d0ea8e09b9e46312e6907b90c8da96c15e0e3ca7d9d9edb8e1a4d56ec085e88a
font_03_cff_off0007279c.bin pdf-font-stream PDF embedded font (cff) at offset 0x7279C 5157 bytes
SHA-256: 07a74de8dcb9003a7c744f1fe17287002527e59f397369c2ad9d153def80c886
embedded_file_obj0008_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 8 at offset 0x74301; filter decode failed 89 bytes
SHA-256: fad811aa1a3aaf424adca37ca88fef38078545a0fa7642613b7faf6043cdcb6c
embedded_file_obj0009_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 9 at offset 0x743B4; filter decode failed 1190 bytes
SHA-256: f3adc66b15fcdeba77e2ed695721bbd26be26953a4cedb2ede0ff2f790270a3e
embedded_file_obj0010_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 10 at offset 0x748B5; filter decode failed 9796 bytes
SHA-256: f2cb1b0db102e39344fb45478ac6ca2c535b58792541b2411655df1c1949ee03
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
embedded_file_obj0011_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 11 at offset 0x76F53; filter decode failed 153 bytes
SHA-256: bb2cf07a90f3ce40ee28a4499e4b3cf3f7782d803ce02b5ee19d8df841d7c77e
embedded_file_obj0013_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 13 at offset 0x77328; filter decode failed 166 bytes
SHA-256: f337a2b40fd6245e78d376407454365ce592d866260765503eb446cad76a8c94
embedded_file_obj0014_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 14 at offset 0x77428; filter decode failed 437 bytes
SHA-256: d8f22ee3ead1a57965f7200a1630dd28fc7d7e8b892d856c0796b6174358aa77
embedded_file_obj0015_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 15 at offset 0x77636; filter decode failed 86 bytes
SHA-256: af56661dbd3e30c12e18dea94e7c3a4db833a3bd865a2870cecd899e1756564c