SUSPICIOUS
36
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
The PDF file contains JavaScript that references several URLs, some of which are associated with Adobe and XFA forms. The document body presents a form for social benefits ('SGB II Antrag auf Weiterbewilligung der Leistungen zur Sicherung des Lebensunterhalts'), suggesting a phishing or information-gathering attempt. The presence of embedded files and JavaScript indicates a potential for malicious actions, such as downloading further payloads or exploiting vulnerabilities.
Machine Learning
- Nyx PDF Classifier clean score 0.0510
Heuristics 6
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.monotype.comMonotype In extracted file (font_02_sfnt_off00027048.bin)
- http://ocsp.verisign.com0In extracted file (font_03_sfnt_off00076751.bin)
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xfa/promoted-desc/In PDF document text
- http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-template/2.8/Referenced by PDF JavaScript
- http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-template/2.5/Referenced by PDF JavaScript
- http://ns.adobe.com/xdp/In extracted file (embedded_file_obj0189.bin)
- http://www.xfa.org/schema/xci/2.8/In extracted file (embedded_file_obj0190.bin)
- http://www.xfa.org/schema/xfa-locale-set/2.1/In extracted file (embedded_file_obj0192.bin)
- http://ns.adobe.com/xfdf/In extracted file (embedded_file_obj0195.bin)
- http://www.xfa.org/schema/xfa-form/2.8/In extracted file (embedded_file_obj0196.bin)
- https://www.verisign.com/rpaIn extracted file (font_02_sfnt_off00027048.bin)
- http://ocsp.verisign.com/ocsp/status0In extracted file (font_02_sfnt_off00027048.bin)
- https://www.verisign.com/rpa0In extracted file (font_02_sfnt_off00027048.bin)
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl0In extracted file (font_02_sfnt_off00027048.bin)
- http://www.microsoft.com/typographyIn extracted file (font_02_sfnt_off00027048.bin)
- http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn extracted file (font_02_sfnt_off00027048.bin)
- http://crl.verisign.com/tss-ca.crl0In extracted file (font_03_sfnt_off00076751.bin)
- http://crl.verisign.com/ThawteTimestampingCA.crl0In extracted file (font_03_sfnt_off00076751.bin)
- https://www.verisign.com/rpa01In extracted file (font_03_sfnt_off00076751.bin)
- http://crl.verisign.com/pca3.crl0In extracted file (font_03_sfnt_off00076751.bin)
- http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DIn extracted file (font_03_sfnt_off00076751.bin)
- http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0In extracted file (font_03_sfnt_off00076751.bin)
- http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlIn extracted file (font_03_sfnt_off00076751.bin)
Extracted artifacts 16
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0189.bin |
pdf-embedded-file | PDF EmbeddedFile object 189 at offset 0x5B1E6 | 163 bytes |
SHA-256: 6a92e1d26e0b74da3eaac0204358dc286d80a38e407516f1a71149607a9887b9 |
|||
embedded_file_obj0190.bin |
pdf-embedded-file | PDF EmbeddedFile object 190 at offset 0x5B2D9 | 1968 bytes |
SHA-256: 384d654330ebd80971db35cc8b3e9570849c2441ff26f195ec4f6980d4645b98 |
|||
embedded_file_obj0191.bin |
pdf-embedded-file | PDF EmbeddedFile object 191 at offset 0x5B653 | 423970 bytes |
SHA-256: a4b2f2854b7f81fd86b175364b1044ee1f0459b3bd72bb36c034caceb9cd02ba |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
2256 of 3514 identifiers look randomly generated (e.g. 'XrhcBIAzoFA4JBYNB4RCYVC4ZDYdD4hEYlE4pFYt'); 13 string-concatenation chain(s) — consistent with name-mangling obfuscation. Carved artifact contains 2 long base64-like blob(s).
|
|||
embedded_file_obj0192.bin |
pdf-embedded-file | PDF EmbeddedFile object 192 at offset 0x75A62 | 2415 bytes |
SHA-256: bac3e4de866ac1448036bb843b9b97f7525c1e48b40f0b6335cf6bfcf93c9858 |
|||
embedded_file_obj0193.bin |
pdf-embedded-file | PDF EmbeddedFile object 193 at offset 0x75D55 | 3869 bytes |
SHA-256: 518dfeab6de10097a64e1247ce07218a7ada8a641b9eecaabf3dd70e266a1f0b |
|||
embedded_file_obj0194.bin |
pdf-embedded-file | PDF EmbeddedFile object 194 at offset 0x76262 | 1856 bytes |
SHA-256: 1a9a939c50d732377ffe1ac5a0a72a9d9e60c518c2293c000c565bd2ead9c3f6 |
|||
embedded_file_obj0195.bin |
pdf-embedded-file | PDF EmbeddedFile object 195 at offset 0x7659F | 80 bytes |
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19 |
|||
embedded_file_obj0196.bin |
pdf-embedded-file | PDF EmbeddedFile object 196 at offset 0x7664A | 56 bytes |
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1 |
|||
stream_002_off00000705.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x705 | 1367 bytes |
SHA-256: f8721569904600df33f536ddc9f4942717077f9d6c3c4253a8f4de5650fc6531 |
|||
stream_003_off000008ed.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x8ED | 902 bytes |
SHA-256: 91ea259764c68d27b8981a339c02d8ea92224ae5c0d0cd0a7c8f3d645d599090 |
|||
stream_018_off00003621.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3621 | 52052 bytes |
SHA-256: a22d44e3d44bc5349053b34b35da1c9b137df3fd2440e73dcc7cae031f1f1666 |
|||
objstm_1242_00.bin |
pdf-objstm-decoded | PDF /ObjStm 1242 0 obj (inflated) | 15790 bytes |
SHA-256: 2074d96620530907368084751f834dd84ce4e5e622a529561220116cae3a936d |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
font_01_sfnt_off0000aada.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAADA | 43970 bytes |
SHA-256: 6c7c620316748540892695692f5f4f36572c5b464cfeafe3970764cb197182da |
|||
font_02_sfnt_off00027048.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x27048 | 352198 bytes |
SHA-256: 1e8564d3d89047875dccaa98279599de9d7ddf77240906041f1156ba8edf3315 |
|||
font_03_sfnt_off00076751.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x76751 | 95975 bytes |
SHA-256: c29e5b1537bee8c88b3ffca56c5f24a45ec8da374cf9d4c0b4a78d04fc230949 |
|||
font_04_sfnt_off00086a36.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x86A36 | 367087 bytes |
SHA-256: b8e2518b116c26bab0e9f8c1672daf405dedad561157502b657e9005be2029aa |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.