Malicious PDF — malware analysis report

Static analysis result for SHA-256 94e7a6130e29698e…

MALICIOUS

PDF

1.34 MB
MD5: 5ed572aa4ed9c8ca1aedb8f57764cc75 SHA-1: 7763d6030b5b129b3ee7e8a197894a2a2604bce5 SHA-256: 94e7a6130e29698e27feaadcac67f1629a0b909f97b100e47cc5c44fbb05bed4
126 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.007 JavaScript

The PDF file contains XFA forms and embedded JavaScript, with high-confidence heuristics indicating JavaScript eval() calls and prototype pollution patterns. The embedded JavaScript streams are heavily obfuscated, but the presence of these indicators suggests the script is designed to download and execute a secondary payload. The PDF structure and the nature of the heuristics point towards a malicious document designed for exploitation or malware delivery.

Heuristics 8

  • Prototype-pollution JavaScript pattern high CVE related PDF_JS_PROTOTYPE_POLLUTION
    PDF JavaScript mutates object prototypes while also referencing privileged or sensitive PDF APIs. This tracks a modern PDF exploit technique family without assigning an unverified CVE.
  • eval() call high PDF_EVAL
    eval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xfa/promoted-desc/

Extracted artifacts 18

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00000126.js
2beb716c7e789150039a33757e5c5eb9887f4e7bd26c4c9f635a5683c7284547
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x126 2367 bytes
stream_002_off000004f4.js
9e7999739a67c91f61e555df4650d4eda3ff97126c5454c880b260b1dc22695e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F4 956712 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
stream_003_off0004eafe.bin
49df4fbd3b6754b8c04bf2166797938fa7cfe4d517441b4fcfc1232673e45e26
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4EAFE 8410 bytes
stream_004_off0004f02f.bin
e41c688e1e1b9a68b01ef7c324245fa1fa5a2a27bb4c274460f4683fc8b7811d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F02F 7294 bytes
stream_005_off0004f629.bin
2850a54cf7b10aa91ac9999a207ae44baee5b1d5267def0dde37317f22d62efa
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F629 425 bytes
stream_009_off00050894.bin
3dc3c5a37cc8ad0c5228661d04df0318b3e0355b902fcf3dcb58208fb15869a6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x50894 554074 bytes
stream_015_off00099f1a.bin
b2a50460b1fc66b7680230c728241859435e1af538bd15e880282e123198de62
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x99F1A 102219 bytes
stream_016_off000ab893.bin
f45f0b80003d1a3e9882b613d3b4c37f1d9d321312ad96a8ced965ec319ede3c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xAB893 189445 bytes
stream_017_off000cb762.bin
7d3196a915fcacee30229cb3ff02d694ce05c02b8c9c8929ec761b8d00bda68d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xCB762 198054 bytes
stream_018_off000ece5e.bin
cce23e8d26eebd19be1c37673129e5435af2d4839a918a86c24db801ee93b79d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xECE5E 364658 bytes
stream_019_off0011f5e3.bin
cc0a7f6ffe60906290d733af5215ccab8d47d1ce6cbe8c028a0caa1560a32b57
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11F5E3 349207 bytes
stream_021_off001530bd.js
f94e41f586bf3f20bc1deeac4bfbda388a61db43f25fbd6304ba73f5653368cf
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1530BD 1313 bytes
stream_022_off0015329e.js
1b2ec98752b966f601d5223a750559cf13d562ac5e5c6d1fcc7217835b01f5fd
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x15329E 902 bytes
objstm_0022_00.bin
8a44bcb732d5eaa29276b109ec67e4f0f52803b7f731f31c356d4436d4c7fa92
pdf-objstm-decoded PDF /ObjStm 22 0 obj (inflated) 22243 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 long base64-like blob(s).
font_00_sfnt_off00056838.bin
c29e5b1537bee8c88b3ffca56c5f24a45ec8da374cf9d4c0b4a78d04fc230949
pdf-font-stream PDF embedded font (sfnt) at offset 0x56838 95975 bytes
font_01_sfnt_off00066b22.bin
4f8a962143becce891b0f8d40b5315e54e2a298ba661302850ebd34e48af909a
pdf-font-stream PDF embedded font (sfnt) at offset 0x66B22 99778 bytes
font_02_sfnt_off00077de2.bin
b1260c85fef77007b5f19c1c6f3552e1c6ade6c959082cf86dd6971951ed119c
pdf-font-stream PDF embedded font (sfnt) at offset 0x77DE2 102071 bytes
font_03_sfnt_off000897ff.bin
926d8eb5abd4c74e46a419aaf25a490564d389c7a250d2392b198a342df65b8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x897FF 97320 bytes