Malicious PDF — malware analysis report

Static analysis result for SHA-256 7953f37d71834cb1…

MALICIOUS

PDF

70.1 KB
MD5: 30e3d58bf287c8429b64eb72db61b9a9 SHA-1: ddab87f7fda4d996fe01f16cc21491368654ccad SHA-256: 7953f37d71834cb11ff5713b1b28729f5a332448b5e3660e8bf5c2a2b75da8e7
158 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains embedded JavaScript that utilizes a Base64-like decoding function, indicated by the `zjjjzjjzs` function and the `unescape` call. This script is designed to deobfuscate and execute further malicious code, likely a second-stage payload. The presence of PDF JavaScript exploit cluster heuristics and ML classification strongly suggests malicious intent. The decoded content is not fully visible due to truncation, but the structure points to a downloader or exploit execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 7

  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • unescape() call high PDF_UNESCAPE
    unescape() found — often used to decode shellcode in PDF JS exploits
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.bitstream.com
    • http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/2.6/
    • http://www.xfa.org/schema/xfa-template/2.6/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_000.js
b34f065679ac9b7a86505d2aef51534dce9e4c19b5c3f69ca696007f109fa573
pdf-javascript-stream PDF /JS object 13 at offset 0x10531 3967 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
javascript_obj0013_001.js
31d217eb7125537bc6f88ab6caaab5fe96c37ea045a6cb09863b11f8205b2732
pdf-javascript-stream PDF /JS object 13 at offset 0x10555 4878 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
font_00_sfnt_off00000352.bin
a8f4d9b7d604c3c8a0bf3f9a31b9e952d467f98d118fdc784d95d689a14d8a33
pdf-font-stream PDF embedded font (sfnt) at offset 0x352 65932 bytes