Malicious PDF — malware analysis report

Static analysis result for SHA-256 61796532bc900a9f…

MALICIOUS

PDF

3.80 MB Created: 2025-09-10 03:22:49 +02:00 Authoring application: Microsoft® Word LTSC
MD5: e99d97be0dc2818ae0c6af3ce0524f0a SHA-1: 29f398af6e845d88becfca316df0456308d92ff2 SHA-256: 61796532bc900a9f4ee9e27680693cfc8f8783d0e2f97db50d0b240a94803253
110 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The file is a PDF containing embedded JavaScript, which is flagged as an exploit cluster related to CVE-2023-26369. This indicates the sample is designed to leverage this vulnerability for code execution. The embedded JavaScript is the primary mechanism for this exploitation, likely leading to the download and execution of further malicious content.

Machine Learning

  • Nyx PDF Classifier clean score 0.0001

Heuristics 4

  • TrueType bitmap font + active content — CVE-2023-26369 related high CVE related PDF_CVE_2023_26369_RELATED
    PDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/pdf/1.3/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://www.microsoft.com/typography/ctfontshttp://www.fonts.comMicrosoft
    • http://www.microsoft.com/typography/fonts/default.aspx
    • http://www.microsoft.com/typography/fonts/Microsoft

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000ff1a.bin
f82b8a3c43c82ad6d31deaec78b195441833b20df52a8ad2f51b742be8479ff9
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xFF1A 113900 bytes
stream_006_off0001a2c5.bin
538290ef9cdd97f0812e81bb46e5f2b7e79b77cb1f9ded5c6a5f35c75cf67816
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1A2C5 4194304 bytes
stream_013_off0001a2c5.bin
6220fd0244d789940d8dd42431c9c400dea74ad4197742ace170adc379872063
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1A2C5 2183659 bytes