Malicious PDF — malware analysis report

Static analysis result for SHA-256 834a67589e2c5477…

MALICIOUS

PDF

161.2 KB First seen: 2026-05-11
MD5: a3cccf6c4f12261321cf55fda110c3f9 SHA-1: 3f088f578f9af9a3b03f3c7a728bfff73f7255d0 SHA-256: 834a67589e2c54778d072b6398667a5b512a826e9c79d8dfd1cc014444900af5
176 Risk Score

🔏 Digital signature Modified after signing

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains JavaScript that attempts to exfiltrate user credentials via an `app.execDialog` call, disguised as a financial aid form. The presence of XFA forms and embedded JavaScript, along with a digitally signed but modified PDF, indicates a sophisticated attempt to bypass security measures. The script likely downloads and executes a second-stage payload, though the exact URL is obfuscated.

Machine Learning

  • Nyx PDF Classifier clean score 0.0158

Heuristics 9

  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
     var str_hinweis = { initialize: function(dialog) {},commit: function(dialog) { var results = dialog.store(); if(results['cb_1'] == true){xfa.resolveNode("Seite1.SAVE_FLAG").rawValue = '1';}  }, cb_1: function (dialog) {this.hasSelected = !this.hasSelected ;}, ok: function(dialog) { }, cancel: function(dialog) { }, description: {name: 'Hinweis', elements: [{type: 'view',align_children: 'align_left', elements: [{ type: 'static_text',name: 'Hinweis:',bold: true,font: 'dialog',height: 20 }, {type:  …
     eval(str_hinweis);
     var ret = app.execDialog(str_hinweis);
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Active content added after the PDF was signed medium PDF_SIGNATURE_POST_SIGN_MODIFICATION
    An incremental update appended AFTER the signed byte range introduces active content (/EmbeddedFile). Some of this can occur in legitimate form-fill (field scripts, a rewritten /Catalog), so it is suspicious rather than damning — but it is content the signer did not approve.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xfa/promoted-desc/In PDF document text
    • http://www.xfa.org/schema/xfa-template/2.8/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.5/Referenced by PDF JavaScript
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In extracted file (embedded_file_obj0104.bin)
    • http://www.xfa.org/schema/xci/2.8/In extracted file (embedded_file_obj0105.bin)
    • http://www.xfa.org/schema/xfa-locale-set/2.7/In extracted file (embedded_file_obj0107.bin)
    • http://www.xfa.org/schema/xfa-locale-set/2.1/In extracted file (embedded_file_obj0107.bin)
    • http://ns.adobe.com/xtd/In extracted file (embedded_file_obj0109.bin)
    • http://ns.adobe.com/xfdf/In extracted file (embedded_file_obj0111.bin)
    • http://www.xfa.org/schema/xfa-form/2.8/In extracted file (embedded_file_obj0112.bin)
    • http://www.w3.org/2001/XMLSchema-instanceIn extracted file (embedded_file_obj1441.bin)

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0104.bin pdf-embedded-file PDF EmbeddedFile object 104 at offset 0xC8C8 163 bytes
SHA-256: a11e6b7b79362f60ad6c1b4fd416ea4b882406ae802afc80b49874ca032594f5
embedded_file_obj0105.bin pdf-embedded-file PDF EmbeddedFile object 105 at offset 0xC9BC 1996 bytes
SHA-256: 815f0d20c35617be582e6d58010db0e77a3c179c04d7f52544736735ba0b67e9
embedded_file_obj0106.bin pdf-embedded-file PDF EmbeddedFile object 106 at offset 0xCD5D 286007 bytes
SHA-256: 3b8e41d3ad4ca11ce43051950767b6139ce5192905b8b0f83da548f52acbe529
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0107.bin pdf-embedded-file PDF EmbeddedFile object 107 at offset 0x16BCE 2483 bytes
SHA-256: 8f7c5ab54f868049d0b4225cd105709fab42364e2af88ad98f2262be600bf8e2
embedded_file_obj0108.bin pdf-embedded-file PDF EmbeddedFile object 108 at offset 0x16EDA 1576 bytes
SHA-256: d14de2f1cb2f6f1caf8f940bcfe9060fc40cad804ee4101e76aa46a6a4b52ae1
embedded_file_obj0109.bin pdf-embedded-file PDF EmbeddedFile object 109 at offset 0x170C1 200 bytes
SHA-256: 500856001a9edb17a299f41c8b34871c12c85d56ec8eff03ef181fca24bb96b5
embedded_file_obj0110.bin pdf-embedded-file PDF EmbeddedFile object 110 at offset 0x171B8 1831 bytes
SHA-256: 853755cbb5b71257ef28f08cb5825a33375555dc8f60cc8436345c5de885092b
embedded_file_obj0111.bin pdf-embedded-file PDF EmbeddedFile object 111 at offset 0x174E1 80 bytes
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
embedded_file_obj0112.bin pdf-embedded-file PDF EmbeddedFile object 112 at offset 0x1758D 56 bytes
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
embedded_file_obj1440.bin pdf-embedded-file PDF EmbeddedFile object 1440 at offset 0x271E6 162 bytes
SHA-256: 17a650b357586088eb15bf2ef8ba901a177911fddfd658ec6fd795280ba4b363
embedded_file_obj1441.bin pdf-embedded-file PDF EmbeddedFile object 1441 at offset 0x272D9 1457 bytes
SHA-256: c60476dfbfafe53e592c08297556caaf44ca4902f9bed63dbb19558528ef4b8e
xfa_image_rawvalue_000.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0xECD1 25788 bytes
SHA-256: a9330de45a637cb5a905f5026974ead8e0afd58541101744d4100ee3591eb1a9
stream_081_off00019bda.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x19BDA 1363 bytes
SHA-256: 529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f
stream_082_off00019dba.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x19DBA 902 bytes
SHA-256: e985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a
objstm_0114_00.bin pdf-objstm-decoded PDF /ObjStm 114 0 obj (inflated) 19509 bytes
SHA-256: a5286822065172144e1ba76e5566bf11bb641e7fbe58a591580b83e3efbe5f8f