PDF static analysis report

Static analysis result for SHA-256 93b79231affafcde…

SUSPICIOUS

PDF

636.9 KB First seen: 2026-05-10
MD5: 14355b62c8a99666caca8f2d1bd2aecb SHA-1: db7bfe2dcd7a0b85248bce1c1d6b8f29a67c39c4 SHA-256: 93b79231affafcde776f150b2e1cb3501373fee5f4b12fdeb88d536ef2d6e182
56 Risk Score

🔏 Digital signature Signed

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file exhibits multiple indicators of malicious intent, including embedded files and JavaScript actions. Specifically, the presence of an embedded script payload and a large embedded file (embedded_file_obj0067.bin) strongly suggests that this document is a dropper or downloader for further malicious activity. The JavaScript action, while not fully detailed, is a common vector for executing embedded payloads.

Machine Learning

  • Nyx PDF Classifier clean score 0.0199

Heuristics 7

  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xfa/promoted-desc/In PDF document text
    • http://ns.adobe.com/xdp/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/2.8/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.5/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.1/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://ns.adobe.com/xtd/In PDF document text
    • http://ns.adobe.com/xfdf/In PDF document text
    • http://ns.adobe.com/photoshop/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
    • http://ns.adobe.com/tiff/1.0/In PDF document text
    • http://ns.adobe.com/exif/1.0/In PDF document text

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0065.bin pdf-embedded-file PDF EmbeddedFile object 65 at offset 0x3F498 163 bytes
SHA-256: 24322a1c240a08476db3cee4060059448ff9031c05b1d741d128363c15899904
embedded_file_obj0066.bin pdf-embedded-file PDF EmbeddedFile object 66 at offset 0x3F58B 2094 bytes
SHA-256: 10b6c07f98f6c5a358e09ff9fe0a9dd7eca02a9ef20f65e9fb850a490c4ca9a0
embedded_file_obj0067.bin pdf-embedded-file PDF EmbeddedFile object 67 at offset 0x3F939 1487647 bytes
SHA-256: 75bb5481666474c67d624b47aa78292ef795a2d4a46ba81b2a60a933d192c024
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0068.bin pdf-embedded-file PDF EmbeddedFile object 68 at offset 0x92E67 2415 bytes
SHA-256: bac3e4de866ac1448036bb843b9b97f7525c1e48b40f0b6335cf6bfcf93c9858
embedded_file_obj0069.bin pdf-embedded-file PDF EmbeddedFile object 69 at offset 0x93159 2284 bytes
SHA-256: c78c7538020250e5a6be6f8bf4a3c162f9ed6de9fd0fa09aa9d8ab2cec9b1a3a
embedded_file_obj0070.bin pdf-embedded-file PDF EmbeddedFile object 70 at offset 0x9347E 200 bytes
SHA-256: 500856001a9edb17a299f41c8b34871c12c85d56ec8eff03ef181fca24bb96b5
embedded_file_obj0071.bin pdf-embedded-file PDF EmbeddedFile object 71 at offset 0x93574 1773 bytes
SHA-256: c6e76bc3dd93782aec849885f7384d3212dfbf621bc26fce2547ca839dbc788c
embedded_file_obj0072.bin pdf-embedded-file PDF EmbeddedFile object 72 at offset 0x9386D 80 bytes
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
embedded_file_obj0073.bin pdf-embedded-file PDF EmbeddedFile object 73 at offset 0x93918 56 bytes
SHA-256: 4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
xfa_image_rawvalue_000.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x419EC 25788 bytes
SHA-256: a9330de45a637cb5a905f5026974ead8e0afd58541101744d4100ee3591eb1a9
xfa_image_rawvalue_001.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x6363D 262144 bytes
SHA-256: d0eb44e620524ec54d46b64a7bc186f2bf09d056b9ae62bb972056e499a528d9
stream_055_off0009630f.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9630F 1367 bytes
SHA-256: f8721569904600df33f536ddc9f4942717077f9d6c3c4253a8f4de5650fc6531
stream_056_off000964f7.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x964F7 902 bytes
SHA-256: 91ea259764c68d27b8981a339c02d8ea92224ae5c0d0cd0a7c8f3d645d599090
objstm_0075_00.bin pdf-objstm-decoded PDF /ObjStm 75 0 obj (inflated) 23693 bytes
SHA-256: 98ba9f469d3691b25a946a16e6c8eed4c08b416b2ce85d00d961d7761dc1d2bb
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 8 long base64-like blob(s).