Malicious PDF — malware analysis report

Static analysis result for SHA-256 94e7a6130e29698e…

MALICIOUS

PDF

1.34 MB First seen: 2012-10-02
MD5: 5ed572aa4ed9c8ca1aedb8f57764cc75 SHA-1: 7763d6030b5b129b3ee7e8a197894a2a2604bce5 SHA-256: 94e7a6130e29698e27feaadcac67f1629a0b909f97b100e47cc5c44fbb05bed4
278 Risk Score

🔏 Digital signature Signed

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1059.007 JavaScript

The PDF file contains XFA forms and embedded JavaScript, with high-confidence heuristics indicating JavaScript eval() calls and prototype pollution patterns. The embedded JavaScript streams are heavily obfuscated, but the presence of these indicators suggests the script is designed to download and execute a secondary payload. The PDF structure and the nature of the heuristics point towards a malicious document designed for exploitation or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7252

Heuristics 9

  • JavaScript action low 4 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Prototype-pollution JavaScript pattern high CVE related PDF_JS_PROTOTYPE_POLLUTION
    PDF JavaScript mutates object prototypes while also referencing privileged or sensitive PDF APIs. This tracks a modern PDF exploit technique family without assigning an unverified CVE.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
      var node = list.item(i);
      el.addItem(eval(node[label]).value, eval(node[val]).value);
     }
  • exportDataObject + nLaunch — embedded-file launch-on-open dropper critical PDF_JS_EXPORT_LAUNCH_DROPPER
    PDF JavaScript calls exportDataObject() with nLaunch set, which extracts the document's embedded file and launches it in its default application. This is a launch-on-open dropper: the embedded file is the payload. No benign workflow auto-launches an extracted PDF attachment. (identified after nested-decoder de-obfuscation)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocsp.verisign.com0 Referenced by PDF JavaScript
    • http://wlsdev2.cc.cec.eu.int:7021/xmlgate/services/XmlgateServiceIn PDF document text
    • http://www.adobe.com/products/acrobat/readstep2.htmlReferenced by PDF JavaScript
    • http://www.adobe.com/support/products/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/Referenced by PDF JavaScript
    • http://ns.adobe.com/pdf/1.3/Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/mm/Referenced by PDF JavaScript
    • http://purl.org/dc/elements/1.1/Referenced by PDF JavaScript
    • http://ns.adobe.com/xfa/promoted-desc/Referenced by PDF JavaScript
    • http://ns.adobe.com/xdp/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/2.8/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.8/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://eacea.ec.europa.euReferenced by PDF JavaScript
    • http://eacea.ec.europa.eu/WSXMLReceiverAx2D/services/WSXMLReceiverReferenced by PDF JavaScript
    • http://eacea.ec.europa.eu/WSXMLReceiverAx2T/services/WSXMLReceiverReferenced by PDF JavaScript
    • http://eacea.ec.europa.eu/WSXMLReceiverAx2P/services/WSXMLReceiverReferenced by PDF JavaScript
    • http://eacea.ec.europa.eu/eforms/index_en.phpReferenced by PDF JavaScript
    • http://www.w3.org/2001/XMLSchema-instanceReferenced by PDF JavaScript
    • http://ec.europa.eu/culture/media/programme/index_en.htmReferenced by PDF JavaScript
    • http://www.eacea.ec.europa.eu/media/filmsReferenced by PDF JavaScript
    • http://ec.europa.eu/media/filmsReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.7/Referenced by PDF JavaScript
    • http://ns.adobe.com/data-description/Referenced by PDF JavaScript
    • http://www.w3.org/2000/01/rdf-schema#Referenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Referenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/ATReferenced by PDF JavaScript
    • http://eacea.ec.europa.eu/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-connection-set/2.8/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-connection-set/2.4/Referenced by PDF JavaScript
    • http://www.w3.org/2001/XMLSchemaReferenced by PDF JavaScript
    • http://www.w3.org/2002/01/xformsReferenced by PDF JavaScript
    • http://crl.verisign.com/tss-ca.crl0Referenced by PDF JavaScript
    • http://crl.verisign.com/ThawteTimestampingCA.crl0Referenced by PDF JavaScript
    • https://www.verisign.com/rpaReferenced by PDF JavaScript
    • https://www.verisign.com/rpa01Referenced by PDF JavaScript
    • http://crl.verisign.com/pca3.crl0Referenced by PDF JavaScript
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DReferenced by PDF JavaScript
    • https://www.verisign.com/rpa0Referenced by PDF JavaScript
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0Referenced by PDF JavaScript
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlReferenced by PDF JavaScript
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlMyriadReferenced by PDF JavaScript
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl0Referenced by PDF JavaScript
    • http://www.microsoft.com/typographyReferenced by PDF JavaScript
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OReferenced by PDF JavaScript
    • http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0Referenced by PDF JavaScript
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://www.adobe.com/supporReferenced by PDF JavaScript
    +30 more URL(s)

Extracted artifacts 18

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00000126.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x126 2367 bytes
SHA-256: 2beb716c7e789150039a33757e5c5eb9887f4e7bd26c4c9f635a5683c7284547
stream_002_off000004f4.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F4 956712 bytes
SHA-256: 9e7999739a67c91f61e555df4650d4eda3ff97126c5454c880b260b1dc22695e
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
stream_003_off0004eafe.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4EAFE 8410 bytes
SHA-256: 49df4fbd3b6754b8c04bf2166797938fa7cfe4d517441b4fcfc1232673e45e26
stream_004_off0004f02f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F02F 7294 bytes
SHA-256: e41c688e1e1b9a68b01ef7c324245fa1fa5a2a27bb4c274460f4683fc8b7811d
stream_005_off0004f629.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F629 425 bytes
SHA-256: 2850a54cf7b10aa91ac9999a207ae44baee5b1d5267def0dde37317f22d62efa
stream_009_off00050894.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x50894 554074 bytes
SHA-256: 3dc3c5a37cc8ad0c5228661d04df0318b3e0355b902fcf3dcb58208fb15869a6
stream_015_off00099f1a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x99F1A 102219 bytes
SHA-256: b2a50460b1fc66b7680230c728241859435e1af538bd15e880282e123198de62
stream_016_off000ab893.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xAB893 189445 bytes
SHA-256: f45f0b80003d1a3e9882b613d3b4c37f1d9d321312ad96a8ced965ec319ede3c
stream_017_off000cb762.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xCB762 198054 bytes
SHA-256: 7d3196a915fcacee30229cb3ff02d694ce05c02b8c9c8929ec761b8d00bda68d
stream_018_off000ece5e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xECE5E 364658 bytes
SHA-256: cce23e8d26eebd19be1c37673129e5435af2d4839a918a86c24db801ee93b79d
stream_019_off0011f5e3.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11F5E3 349207 bytes
SHA-256: cc0a7f6ffe60906290d733af5215ccab8d47d1ce6cbe8c028a0caa1560a32b57
stream_021_off001530bd.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1530BD 1313 bytes
SHA-256: f94e41f586bf3f20bc1deeac4bfbda388a61db43f25fbd6304ba73f5653368cf
stream_022_off0015329e.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x15329E 902 bytes
SHA-256: 1b2ec98752b966f601d5223a750559cf13d562ac5e5c6d1fcc7217835b01f5fd
objstm_0022_00.bin pdf-objstm-decoded PDF /ObjStm 22 0 obj (inflated) 22243 bytes
SHA-256: 8a44bcb732d5eaa29276b109ec67e4f0f52803b7f731f31c356d4436d4c7fa92
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 long base64-like blob(s).
font_00_sfnt_off00056838.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x56838 95975 bytes
SHA-256: c29e5b1537bee8c88b3ffca56c5f24a45ec8da374cf9d4c0b4a78d04fc230949
font_01_sfnt_off00066b22.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x66B22 99778 bytes
SHA-256: 4f8a962143becce891b0f8d40b5315e54e2a298ba661302850ebd34e48af909a
font_02_sfnt_off00077de2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x77DE2 102071 bytes
SHA-256: b1260c85fef77007b5f19c1c6f3552e1c6ade6c959082cf86dd6971951ed119c
font_03_sfnt_off000897ff.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x897FF 97320 bytes
SHA-256: 926d8eb5abd4c74e46a419aaf25a490564d389c7a250d2392b198a342df65b8a