PDF static analysis report

Static analysis result for SHA-256 62c9183f2a25b2d0…

SUSPICIOUS

PDF

124.7 KB Authoring application: Skia/PDF m75 First seen: 2020-09-24
MD5: f29517aebb68c8a13cbe79402082b209 SHA-1: f145cd325eccaf7fa1ae8cabb636d6e5e64f9405 SHA-256: 62c9183f2a25b2d01f4798cae0fb0015d5155bad4e4ae28df99b06b09d356009
48 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript

The PDF contains embedded JavaScript that triggers a print dialog when opened. This is often used to obscure malicious activity or to lure users into a false sense of legitimacy. The embedded URL is also suspicious. While the exact intent is unclear without further context, the print action is a common lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.5673

Heuristics 3

  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.ascendercorp.com/ In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0003_000.js pdf-javascript-stream PDF /JS object 3 at offset 0xB9 55 bytes
SHA-256: 31891b256fb2c725efed8b2bbf38a5e15a3a35b583d76d8b3fb5ee6c8b85f769
Preview script
First 1,000 lines of the extracted script
this.print({bUI:true,bSilent:false,bShrinkToFit:true});
font_00_sfnt_off00001f5b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x1F5B 16488 bytes
SHA-256: 632d88792a5a070cc121c51fdb0c193d1df20c4a40032c4f67986d091d13af99