Malicious PDF — malware analysis report

Static analysis result for SHA-256 6357253f3c42320f…

MALICIOUS

PDF

849.4 KB Created: 2010-03-16 10:01:41 -07:00 Authoring application: Adobe InDesign CS4 (6.0) (via Adobe PDF Library 9.0) First seen: 2026-05-11
MD5: 9ad03610e5baabfac1b8576102f126b2 SHA-1: ae2602713b48f60f942538dc280f8a51cd773e3f SHA-256: 6357253f3c42320f63111277973c6793b2d0f847ee4cf7a5a996ddb15b220550
240 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF sample contains embedded JavaScript that utilizes functions like String.fromCharCode and getAnnots, and triggers eval() calls, indicating malicious intent. The presence of PDF_JPX_CVE_2018_4990_RELATED and PDF_U3D_CVE_RELATED heuristics suggests exploitation of known PDF vulnerabilities. The embedded JavaScript likely attempts to download and execute a second-stage payload from one of the identified URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8340

Heuristics 8

  • JPXDecode + active content — JPEG2000 CVE-family indicator high CVE related PDF_JPX_CVE_2018_4990_RELATED
    PDF uses /JPXDecode (JPEG2000) alongside JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader JPEG2000 parser exploit families, including CVE-2018-4990, but does not prove the exact malformed JP2/JPX primitive.
  • U3D/3D content in PDF — Adobe Reader 3D parser CVE-family indicator high CVE related PDF_U3D_CVE_RELATED
    PDF contains U3D (Universal 3D) or 3D annotation content — CVE-2011-2462 and CVE-2009-3953 are critical vulnerabilities in Adobe Reader's U3D processing that allow arbitrary code execution. U3D content in PDFs is extremely rare in normal documents.
  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
                         toolbarButtonX+width, toolbarButtonY-height ];
            var path = eval("IMAGE_PATH");
            this.button = doc.addField({
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.kaon.com/aboutPDF Referenced by PDF JavaScript
    • http://www.strata.com/rd/live3dmenu.htmlReferenced by PDF JavaScript
    • http://w.taacmr/iedeuhmReferenced by PDF JavaScript
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/g/img/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/t/pg/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/Dimensions#In PDF document text
    • http://ns.adobe.com/xap/1.0/g/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceEvent#In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ManifestItem#In PDF document text
    • http://ns.adobe.com/xmp/InDesign/privateIn PDF document text

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0406_000.js pdf-javascript-stream PDF /JS object 406 at offset 0xD3394 32 bytes
SHA-256: 578aed31eeb16c7d5addb14deabb33c6d1ff616db3cf6757e3c42ed2a6f5cd20
Preview script
First 1,000 lines of the extracted script
toolbar['ZoomInButton'].press();
javascript_obj0408_001.js pdf-javascript-stream PDF /JS object 408 at offset 0xD34E7 33 bytes
SHA-256: cb0b3d4c5f194e021b9a0221da3eb5e452e0eca53b84aa0f617c46eec75a9684
Preview script
First 1,000 lines of the extracted script
toolbar['ZoomOutButton'].press();
javascript_obj0418_004.js pdf-javascript-stream PDF /JS object 418 at offset 0xD3B7E 33 bytes
SHA-256: ef3ea8a689375d1da4f1dc9d6cd8cab6faef31e75fc06dc5a4a8f1b59794f706
Preview script
First 1,000 lines of the extracted script
toolbar['MeasureButton'].press();
stream_002_off000004a5.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4A5 40153 bytes
SHA-256: 6f22ebc6d14801a4c70f679332717a9523edef48c0bcd7588086be8b3669f014
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 15 eval/decoder/string-building token(s).
stream_031_off0001ebf1.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1EBF1 471564 bytes
SHA-256: d76eb683bf59804329c6415801f74bb0efe581a47992b4679e7b786355019205
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.87, consistent with packed or encrypted content.
stream_032_off0008d899.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8D899 92994 bytes
SHA-256: 5e4466127e58b0736f80dd9403acd8bdbe886be31e6d9f951f74116f8b39955a
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 3 eval/decoder/string-building token(s).
objstm_0360_00.bin pdf-objstm-decoded PDF /ObjStm 360 0 obj (inflated) 4437 bytes
SHA-256: a4f07c689288bdd58732900f4c71ef42b26d3c313bd731566d9075715935e090
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
objstm_0060_00.bin pdf-objstm-decoded PDF /ObjStm 60 0 obj (inflated) 8638 bytes
SHA-256: 17919afaa47e46b0d65fa1d2613cc80472f97a9e92be9c50edd5a91e89e5062c
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
objstm_0425_00.bin pdf-objstm-decoded PDF /ObjStm 425 0 obj (inflated) 3127 bytes
SHA-256: e33fe476d011f62d5b3cbbf6a6bece98609791ec38b0fa9f6d43d0141adeb99e
font_00_cff_off000045d6.bin pdf-font-stream PDF embedded font (cff) at offset 0x45D6 5762 bytes
SHA-256: efb892fedc535b39bed7edff6cd8c7b16d628dcc0ad0df8937593d749ab0fdc0
font_01_cff_off000058ae.bin pdf-font-stream PDF embedded font (cff) at offset 0x58AE 3172 bytes
SHA-256: 150e17044d4879b1353de1765b24d85b0b93e36bd3fc961aa3d9bbd044e83f57
font_02_cff_off000071f8.bin pdf-font-stream PDF embedded font (cff) at offset 0x71F8 1292 bytes
SHA-256: 9ae12b2d01497b5b6126cafe9f9d160f7448874c32a46ea600f22848d1355f63
font_03_cff_off0001a89d.bin pdf-font-stream PDF embedded font (cff) at offset 0x1A89D 870 bytes
SHA-256: 7ac0d42f0bd97cbd69bc489433a62995fe8030376befb5f0ff88fcc2daeb1c1f