🔏 Digital signature Signed
A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.
Malware Insights
The PDF file contains multiple embedded JavaScript streams and XFA form elements, including buttons with actions. These elements are often used to execute malicious code or redirect users to malicious sites. The presence of JavaScript actions and embedded JS streams strongly suggests an attempt to exploit user interaction within the PDF. The document body is heavily corrupted, preventing a clear understanding of its lure, but the technical indicators point towards a malicious script execution attempt.
Machine Learning
- Nyx PDF Classifier suspicious score 0.4461
Heuristics 6
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.monotype.comMonotype In PDF document text
- http://www.w3.org/1999/xhtmlIn PDF document text
- http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/iX/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
-
Validly signed PDF form without harmful behavior info PDF_VALID_SIGNATURE_BENIGN_FORMThe PDF has a cryptographically valid signature and the remaining signals are limited to benign form/document structure. No exploit primitive, post-sign active-content mutation, launch action, embedded payload, suspicious external URL, AV/ML hit, or dangerous JavaScript was found, so the low-confidence form findings were lifted to clean.
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0609_000.js |
pdf-javascript-stream | PDF /JS object 609 at offset 0x13072 | 38 bytes |
SHA-256: 6f4ebd4f520911136751e3878ad4b37118b4c12f3bcf22c8ada375ca49290802 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Format(2, 3, 0, 0, "", true); |
|||
javascript_obj0610_001.js |
pdf-javascript-stream | PDF /JS object 610 at offset 0x130C2 | 41 bytes |
SHA-256: 969138dc842bacdbedfeaf4aaf6e3a512fdc0a2d7ed5d6a300c5a280fccb3bd0 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Keystroke(2, 3, 0, 0, "", true); |
|||
javascript_obj0613_002.js |
pdf-javascript-stream | PDF /JS object 613 at offset 0x131B8 | 38 bytes |
SHA-256: d01aa0c07a077ec23f69b8fd9ccdaa6826882e0b2e7e446039ebdd1d983fffcc |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Format(0, 1, 0, 0, "", true); |
|||
javascript_obj0614_003.js |
pdf-javascript-stream | PDF /JS object 614 at offset 0x13208 | 41 bytes |
SHA-256: 3e3d0e421d915769fa631911550fb2593579e6bb9a99fb9158381ac8e8f07fe2 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Keystroke(0, 1, 0, 0, "", true); |
|||
javascript_obj0106_005.js |
pdf-javascript-stream | PDF /JS object 106 at offset 0x1A9E7 | 33 bytes |
SHA-256: c4287c5c3e37d48b98ace11b04930d19e8be4d405af6749d7e51f8d70a59029e |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFDate_KeystrokeEx("dd.mm.yyyy");
|
|||
stream_150_off00029f7b.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x29F7B | 293120 bytes |
SHA-256: 3463cb6a96f307e7e3d7300dfb47d1a354c957c464dadd2539dcb8dc271d2635 |
|||
font_00_cff_off0000e318.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xE318 | 7644 bytes |
SHA-256: 8bd208f0d92e1ac91dca18c911fb647a55b4cec9340b562d668d3760b78f3b5b |
|||
font_01_cff_off0001055b.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x1055B | 4594 bytes |
SHA-256: 06e4a5af36534308a756f356af6dfde4a14784983fea2d73b2d5b706f57ac611 |
|||
font_02_cff_off00011cd9.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x11CD9 | 1871 bytes |
SHA-256: 9657f635fd8c995df978d9aed81c78e4474ce9d4f9939b725401d056f5afa110 |
|||
font_03_cff_off0001296a.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x1296A | 837 bytes |
SHA-256: 5210282752398183162c0f5fb52bf0e058537043c964216e041c7bce588584e6 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.