PDF static analysis report

Static analysis result for SHA-256 3503f2eaad245156…

CLEAN

PDF

540.6 KB Created: -001-1-1-1-1-1-00'30' Authoring application: PScript5.dll Version 5.2.2 (via Acrobat Distiller 7.0 (Windows)) First seen: 2026-05-10
MD5: 54597c4f5d8e1d7ede991c215b2aa40f SHA-1: 1277c22503f6772f8277f6ed6b31beb59feb4fb7 SHA-256: 3503f2eaad2451566d6f785269cdced5c3b18eac1fec912d3ac2ab403eec15d5
15 Risk Score

🔏 Digital signature Signed

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF file contains multiple embedded JavaScript streams and XFA form elements, including buttons with actions. These elements are often used to execute malicious code or redirect users to malicious sites. The presence of JavaScript actions and embedded JS streams strongly suggests an attempt to exploit user interaction within the PDF. The document body is heavily corrupted, preventing a clear understanding of its lure, but the technical indicators point towards a malicious script execution attempt.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4461

Heuristics 6

  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.monotype.comMonotype In PDF document text
    • http://www.w3.org/1999/xhtmlIn PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/iX/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
  • Validly signed PDF form without harmful behavior info PDF_VALID_SIGNATURE_BENIGN_FORM
    The PDF has a cryptographically valid signature and the remaining signals are limited to benign form/document structure. No exploit primitive, post-sign active-content mutation, launch action, embedded payload, suspicious external URL, AV/ML hit, or dangerous JavaScript was found, so the low-confidence form findings were lifted to clean.

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0609_000.js pdf-javascript-stream PDF /JS object 609 at offset 0x13072 38 bytes
SHA-256: 6f4ebd4f520911136751e3878ad4b37118b4c12f3bcf22c8ada375ca49290802
Preview script
First 1,000 lines of the extracted script
AFNumber_Format(2, 3, 0, 0, "", true);
javascript_obj0610_001.js pdf-javascript-stream PDF /JS object 610 at offset 0x130C2 41 bytes
SHA-256: 969138dc842bacdbedfeaf4aaf6e3a512fdc0a2d7ed5d6a300c5a280fccb3bd0
Preview script
First 1,000 lines of the extracted script
AFNumber_Keystroke(2, 3, 0, 0, "", true);
javascript_obj0613_002.js pdf-javascript-stream PDF /JS object 613 at offset 0x131B8 38 bytes
SHA-256: d01aa0c07a077ec23f69b8fd9ccdaa6826882e0b2e7e446039ebdd1d983fffcc
Preview script
First 1,000 lines of the extracted script
AFNumber_Format(0, 1, 0, 0, "", true);
javascript_obj0614_003.js pdf-javascript-stream PDF /JS object 614 at offset 0x13208 41 bytes
SHA-256: 3e3d0e421d915769fa631911550fb2593579e6bb9a99fb9158381ac8e8f07fe2
Preview script
First 1,000 lines of the extracted script
AFNumber_Keystroke(0, 1, 0, 0, "", true);
javascript_obj0106_005.js pdf-javascript-stream PDF /JS object 106 at offset 0x1A9E7 33 bytes
SHA-256: c4287c5c3e37d48b98ace11b04930d19e8be4d405af6749d7e51f8d70a59029e
Preview script
First 1,000 lines of the extracted script
AFDate_KeystrokeEx("dd.mm.yyyy");
stream_150_off00029f7b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x29F7B 293120 bytes
SHA-256: 3463cb6a96f307e7e3d7300dfb47d1a354c957c464dadd2539dcb8dc271d2635
font_00_cff_off0000e318.bin pdf-font-stream PDF embedded font (cff) at offset 0xE318 7644 bytes
SHA-256: 8bd208f0d92e1ac91dca18c911fb647a55b4cec9340b562d668d3760b78f3b5b
font_01_cff_off0001055b.bin pdf-font-stream PDF embedded font (cff) at offset 0x1055B 4594 bytes
SHA-256: 06e4a5af36534308a756f356af6dfde4a14784983fea2d73b2d5b706f57ac611
font_02_cff_off00011cd9.bin pdf-font-stream PDF embedded font (cff) at offset 0x11CD9 1871 bytes
SHA-256: 9657f635fd8c995df978d9aed81c78e4474ce9d4f9939b725401d056f5afa110
font_03_cff_off0001296a.bin pdf-font-stream PDF embedded font (cff) at offset 0x1296A 837 bytes
SHA-256: 5210282752398183162c0f5fb52bf0e058537043c964216e041c7bce588584e6