Malware Insights
The PDF contains embedded JavaScript, indicated by multiple PDF_JAVASCRIPT and PDF_JS heuristic firings. The document body text, though garbled, suggests form fields for personal information such as name, date of birth, and address. The embedded JavaScript functions like AFNumber_Format and AFDate_Keystroke are commonly used to validate user input in forms, supporting the hypothesis that this document is designed to collect sensitive user data. The presence of these elements suggests a phishing or identity theft attempt, likely delivered as a spearphishing attachment.
Machine Learning
- Nyx PDF Classifier clean score 0.1328
Heuristics 4
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.monotype.comMonotype In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
Extracted artifacts 12
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0268_000.js |
pdf-javascript-stream | PDF /JS object 268 at offset 0xC310 | 39 bytes |
SHA-256: 591e64186a9bdbc0043d7787f7855be1cc3018e3082754b8e04d52f0e1f121a1 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Format(2, 2, 0, 0, "�", true); |
|||
javascript_obj0269_001.js |
pdf-javascript-stream | PDF /JS object 269 at offset 0xC361 | 42 bytes |
SHA-256: 1c84a61d4f2b5ad3e6113ed6ad2e7e5699b21e3ff0c7eecaccfce1a13d2be25d |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Keystroke(2, 2, 0, 0, "�", true); |
|||
javascript_obj0271_003.js |
pdf-javascript-stream | PDF /JS object 271 at offset 0xC3FD | 33 bytes |
SHA-256: c4287c5c3e37d48b98ace11b04930d19e8be4d405af6749d7e51f8d70a59029e |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFDate_KeystrokeEx("dd.mm.yyyy");
|
|||
javascript_obj0029_004.js |
pdf-javascript-stream | PDF /JS object 29 at offset 0x11F15 | 38 bytes |
SHA-256: ff0b1e0798b55aee9e494d4b5046c0d747ee05557796f33002cd8f8168a10b67 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Format(0, 3, 0, 0, "", true); |
|||
javascript_obj0046_005.js |
pdf-javascript-stream | PDF /JS object 46 at offset 0x12C72 | 41 bytes |
SHA-256: 6aeb2fc8f6b0dba7b9d76914b437aa0140bcd183b4c2b0d2b66173e7a39a1974 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Keystroke(2, 2, 0, 0, "", true); |
|||
javascript_obj0072_006.js |
pdf-javascript-stream | PDF /JS object 72 at offset 0x13F10 | 38 bytes |
SHA-256: dd4e86ff46931388298d522a0c25afc2a74df361f28fb6ad9f104ffc1f5056c1 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Format(2, 2, 0, 0, "", true); |
|||
javascript_obj0078_007.js |
pdf-javascript-stream | PDF /JS object 78 at offset 0x1430A | 41 bytes |
SHA-256: 5b4e1a57bf6476c87a1db4d415eeb42e1477d446a4236b8ae4189d3d8f669dde |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFNumber_Keystroke(0, 3, 0, 0, "", true); |
|||
stream_114_off000178af.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x178AF | 293120 bytes |
SHA-256: 3463cb6a96f307e7e3d7300dfb47d1a354c957c464dadd2539dcb8dc271d2635 |
|||
font_00_cff_off000057d4.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x57D4 | 5186 bytes |
SHA-256: b9ef3ab45e1a18439cb3b4454d84939ced61fd5c616d46060ffeebe455578654 |
|||
font_01_cff_off00006e76.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x6E76 | 8022 bytes |
SHA-256: a0fa2467ba0f872439c72fc5d8f78a580e7a29b8aad7093f2dd8d2b26f4a7662 |
|||
font_02_cff_off0000d21b.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xD21B | 1871 bytes |
SHA-256: 14c48263da8b9ee77614a83f947df4b509af017095a412a63e405da4341d84d0 |
|||
font_03_cff_off0000db5c.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0xDB5C | 837 bytes |
SHA-256: 0f0c1bc3187e008ee18b6d87175e7e993910e0b6ea582898da0f4315d21e9b90 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.