SUSPICIOUS
38
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious File
The PDF file contains multiple heuristic firings related to embedded JavaScript and embedded script payloads. The presence of an embedded script payload and a suspicious extracted artifact named 'objstm_0053_00.bin' suggests that the document is designed to deliver and execute malicious code. The JavaScript action and embedded JS stream indicate the script's likely intent is to download and execute a second-stage payload.
Machine Learning
- Nyx PDF Classifier clean score 0.0470
Heuristics 7
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
-
Embedded script payload in PDF stream info PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.terrafair.org Referenced by PDF JavaScript
- http://www.yacao.comReferenced by PDF JavaScript
- http://www.fundopo.orgReferenced by PDF JavaScript
- http://}{\rtlch\fcs1In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
- http://ns.adobe.com/xdp/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xci/2.8/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-template/2.8/Referenced by PDF JavaScript
- http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-locale-set/2.7/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-locale-set/2.1/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
- http://ns.adobe.com/xtd/In PDF document text
Extracted artifacts 16
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0008.bin |
pdf-embedded-file | PDF EmbeddedFile object 8 at offset 0x1011F | 86 bytes |
SHA-256: f7ee3ef2f8f35d669a6c2b8b0b0ee89655bbc3d04b107a8d22531830f6fc28a1 |
|||
embedded_file_obj0009.bin |
pdf-embedded-file | PDF EmbeddedFile object 9 at offset 0x101D2 | 1571 bytes |
SHA-256: 182ad621dbe33d40217f587e57126f2ad06cd1448eb1cb3cc8039802a57dacec |
|||
embedded_file_obj0010.bin |
pdf-embedded-file | PDF EmbeddedFile object 10 at offset 0x104D1 | 4145 bytes |
SHA-256: f64afcb34a5de50edc580966413e82006785a79cd78c259824ed955ab5a3f981 |
|||
embedded_file_obj0011.bin |
pdf-embedded-file | PDF EmbeddedFile object 11 at offset 0x10A04 | 150 bytes |
SHA-256: 720c47f19e6a058099295d18a16b7149cc73fe497eb78821ea810f3192228dc4 |
|||
embedded_file_obj0012.bin |
pdf-embedded-file | PDF EmbeddedFile object 12 at offset 0x10AD6 | 2917 bytes |
SHA-256: aafb31c49fd20a0922813ca9f195e935219e227be7c7eadb0584774a6039f751 |
|||
embedded_file_obj0013.bin |
pdf-embedded-file | PDF EmbeddedFile object 13 at offset 0x10E4F | 200 bytes |
SHA-256: 4cb349134bdb5f1a1c03281df9b53128ebe947f235398a912a4f0a9f638b24d5 |
|||
embedded_file_obj0014.bin |
pdf-embedded-file | PDF EmbeddedFile object 14 at offset 0x10F43 | 835 bytes |
SHA-256: 0f56e9453b5452fe512d513a146bc6c894260b647799689d45dc9ac75cbfd7be |
|||
embedded_file_obj0015.bin |
pdf-embedded-file | PDF EmbeddedFile object 15 at offset 0x1111C | 56 bytes |
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1 |
|||
stream_002_off000003e6.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3E6 | 1532 bytes |
SHA-256: f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8 |
|||
stream_003_off000005d1.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x5D1 | 870 bytes |
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb |
|||
objstm_0053_00.bin |
pdf-objstm-decoded | PDF /ObjStm 53 0 obj (inflated) | 6809 bytes |
SHA-256: 1b6f1a286de7ff974ff2c025e96f2714ab9561ef5650a3e37ec8db254e168537 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
font_00_cff_off00003124.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x3124 | 2380 bytes |
SHA-256: 0d6aa82ee6706ca0772c57f20f886047d231ac40532b2a891ba148c1e213134a |
|||
font_01_cff_off000039e3.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x39E3 | 5431 bytes |
SHA-256: 34d9b7480f06bb61863f36413240d75b23e8269ceddb3025f8ad6111111a888b |
|||
font_02_cff_off00004cf7.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x4CF7 | 6728 bytes |
SHA-256: ec340db54265b94738bceb0980be180bdaa6e954fce7e45acbf63f594e912a2a |
|||
font_03_cff_off00006201.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x6201 | 1907 bytes |
SHA-256: 0efa17a73655717d90daa657bd5689d04e3ae001ba9a9dbe61c40c2644731741 |
|||
font_04_cff_off0000fdba.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xFDBA | 127 bytes |
SHA-256: de7dda32f1ec98148cabd32cec59d391f48eb240ff47f8fea4183fb92b3b4b09 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.