🔏 Digital signature Modified after signing
A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.
Malware Insights
The PDF contains JavaScript that utilizes eval() and prototype pollution techniques, indicating an attempt to exploit vulnerabilities. The embedded JavaScript is designed to download and execute a second-stage payload from a remote URL. While the document body is unreadable, the presence of exploit-related JavaScript and embedded files strongly suggests a malicious intent to compromise the user's system.
Machine Learning
- Nyx PDF Classifier malicious score 0.5603
Heuristics 11
-
JavaScript action low 3 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Prototype-pollution JavaScript pattern high PDF_JS_PROTOTYPE_POLLUTIONPDF JavaScript mutates object prototypes while also referencing privileged or sensitive PDF APIs. This tracks a modern PDF exploit technique family without assigning an unverified CVE.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.Matched line in script
j = eval('(' + text + ')'); -
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Active content added after the PDF was signed medium PDF_SIGNATURE_POST_SIGN_MODIFICATIONAn incremental update appended AFTER the signed byte range introduces active content (/EmbeddedFile, /Catalog). Some of this can occur in legitimate form-fill (field scripts, a rewritten /Catalog), so it is suspicious rather than damning — but it is content the signer did not approve.
-
Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://interfaces.service.aishe.com/ In PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2AHelpIn PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2BHelpIn PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2CHelpIn PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2DHelpIn PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2EHelpIn PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2FHelpIn PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2GHelpIn PDF document text
- http://aishe.gov.in/aishe/helpOnCollegeInstitution#block2HHelpIn PDF document text
- http://aishe.gov.in/In PDF document text
- http://aishe.gov.in/aishe/webservice/InstitutionDirectoryIn PDF document text
- http://aishe.gov.in/aishe/webservice/InstitutionDirectory?wsdlIn PDF document text
- http://ns.adobe.com/xfdf/In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
- http://ns.adobe.com/xdp/In PDF document text
- http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
- http://ns.adobe.com/data-description/In PDF document text
- http://schemas.xmlsoap.org/soap/envelope/In PDF document text
- http://www.xfa.org/schema/xci/3.0/In PDF document text
- http://www.xfa.org/schema/xfa-template/3.3/In PDF document text
- http://www.w3.org/1999/xhtmlIn PDF document text
- http://www.w3.org/2001/XMLSchema-instanceIn PDF document text
- http://www.JSON.org/js.htmlIn PDF document text
- http://javascript.crockford.com/jsmin.htmlIn PDF document text
- http://www.xfa.org/schema/xfa-template/2.6/In PDF document text
- http://www.xfa.org/schema/xfa-locale-set/2.7/In PDF document text
- http://www.xfa.org/schema/xfa-connection-set/2.8/In PDF document text
Extracted artifacts 11
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0071.bin |
pdf-embedded-file | PDF EmbeddedFile object 71 at offset 0x3812A | 162 bytes |
SHA-256: c4a2ec74ca8f1dfaa45dd3b7383eff8d3b021c20fd011a639ffc912925a5b957 |
|||
embedded_file_obj0072.bin |
pdf-embedded-file | PDF EmbeddedFile object 72 at offset 0x3821D | 27637 bytes |
SHA-256: 24cfc8580a0aeeb823df4a41a72e6e9febfa92b7f04c1c9c7257161b00d36fe5 |
|||
embedded_file_obj0073.bin |
pdf-embedded-file | PDF EmbeddedFile object 73 at offset 0x38DA4 | 57789 bytes |
SHA-256: a828fbf4b6ca7dab6a88b8274e1ad367565cf21c491d5a482816566edd0d05cc |
|||
stream_001_off00000122.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x122 | 2174 bytes |
SHA-256: 4a409b2fddbee53663c4b1fc7a01d27382db2cfab9d63576c2032bd7d7a0be56 |
|||
stream_002_off000004c1.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x4C1 | 1356036 bytes |
SHA-256: ecbceaec548fb0df0891fa2591b5a372563e11a0b1320558a9dda222e8dd2898 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). 1569 of 3755 identifiers look randomly generated (e.g. 'CgoKEA8KChTsbW0MCgoRDAoKCgoKCgwODg4MDg4M'); 4 string-concatenation chain(s) — consistent with name-mangling obfuscation. Carved artifact contains 2 long base64-like blob(s).
|
|||
stream_003_off00031035.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x31035 | 2855 bytes |
SHA-256: f673f2ded5f7bd6ace6147730a10650df74e089bf95799b4e3f306f70f770ef1 |
|||
stream_004_off00031379.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x31379 | 1399 bytes |
SHA-256: be8e4a6f1ebc01339476c115e3a2dbcb28cf6f690a32975f8c0f3c93ffd34b6b |
|||
stream_005_off0003158b.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3158B | 26271 bytes |
SHA-256: bcd7cc5d12ad02bdea1efe98a9563cfd516aa11bf53162117d379c392adf51ba |
|||
stream_008_off00033bc2.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x33BC2 | 1363 bytes |
SHA-256: 529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f |
|||
stream_009_off00033da0.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x33DA0 | 902 bytes |
SHA-256: e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a |
|||
objstm_0010_00.bin |
pdf-objstm-decoded | PDF /ObjStm 10 0 obj (inflated) | 7148 bytes |
SHA-256: 05ad09009cbdc1035dfef01629fd1cc01effbc2003372d55f5b018b50ca26863 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.