PDF static analysis report

Static analysis result for SHA-256 9e42be77acce500e…

SUSPICIOUS

PDF

502.7 KB First seen: 2026-05-09
MD5: 9eac81b8fcc8eda15d93e4a31a34cb2a SHA-1: 8186694ba68cec910313f5db149c9e095bd92e4f SHA-256: 9e42be77acce500e9b10aafd56a11a0db118d3237ec425379d630de85a5cbb26
52 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution

The ML classifier strongly indicates maliciousness (0.992892). The PDF contains embedded content and XFA forms, common vectors for exploiting vulnerabilities. Although the document body is unreadable and no scripts were extracted, the presence of embedded files and the high ML score suggest the PDF is designed to deliver a secondary payload. The embedded URLs are all confirmed benign, so they are not considered IOCs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9929

Heuristics 5

  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Encrypted PDF (string and stream contents are opaque to static scan) info PDF_ENCRYPTED
    PDF declares /Encrypt — string objects and stream contents are encrypted with the standard security handler (RC4 or AES). On its own this is informational; legitimate encrypted documents include signed contracts, billing statements, and rights-managed material. Static heuristics cannot inspect encrypted payload bytes.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://my.newsaktuell.net/ In PDF document text
    • http://www.monotype.comMonotypeIn PDF document text
    • http://ocsp.verisign.com0In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xfa/promoted-desc/In PDF document text
    • http://ns.adobe.com/xdp/In PDF document text
    • http://www.xfa.org/schema/xci/2.6/In PDF document text
    • http://www.xfa.org/schema/xci/2.8/In PDF document text
    • http://www.xfa.org/schema/xfa-template/2.6/In PDF document text
    • http://www.w3.org/1999/xhtmlIn PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://get.adobe.com/de/reader/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.7/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.6/In PDF document text
    • http://www.xfa.org/schema/xfa-form/2.8/In PDF document text
    • http://ns.adobe.com/xtd/In PDF document text
    • http://ns.adobe.com/xfdf/In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateIn PDF document text
    • http://www.iec.chIn PDF document text
    • https://www.verisign.com/rpaIn PDF document text
    • http://ocsp.verisign.com/ocsp/status0In PDF document text
    • https://www.verisign.com/rpa0In PDF document text
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl0In PDF document text
    • http://www.microsoft.com/typographyIn PDF document text
    • http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
    • http://crl.verisign.com/tss-ca.crl0In PDF document text
    • http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
    • https://www.verisign.com/rpa01In PDF document text
    • http://crl.verisign.com/pca3.crl0In PDF document text
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DIn PDF document text
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0In PDF document text
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlIn PDF document text

Extracted artifacts 24

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0012.bin pdf-embedded-file PDF EmbeddedFile object 12 at offset 0x228B 163 bytes
SHA-256: feb893f013d2a6a966805458699e5913b1ed9570bd0b4b6f23f6f78dbf37cd65
embedded_file_obj0013.bin pdf-embedded-file PDF EmbeddedFile object 13 at offset 0x237E 2235 bytes
SHA-256: 2281957a218b9b40f35ddd520a0b2199d5dd47e5bf1f6981ae08c0c8ae66d78e
embedded_file_obj0014.bin pdf-embedded-file PDF EmbeddedFile object 14 at offset 0x2751 55808 bytes
SHA-256: 0831fb8ce3758ee2ef08c071169d16d4167f96d98d4e34a57e11c1a3bfde8362
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0015.bin pdf-embedded-file PDF EmbeddedFile object 15 at offset 0x82F5 2920 bytes
SHA-256: f188fa029293f05c9305c345589331bd7a57e5fe237839a72ea8396bb778867e
embedded_file_obj0016.bin pdf-embedded-file PDF EmbeddedFile object 16 at offset 0x8672 464 bytes
SHA-256: 15e4143357b9364d6c7c1161f35170770ccd57980ffd427070bff35ea69d49ff
embedded_file_obj0017.bin pdf-embedded-file PDF EmbeddedFile object 17 at offset 0x87B0 121 bytes
SHA-256: 90938f9e3cdf6db2eeee31ed7c949f3b0952b799b670df73d2e56d31bfcc8d34
embedded_file_obj0018.bin pdf-embedded-file PDF EmbeddedFile object 18 at offset 0x886E 200 bytes
SHA-256: d02d151e384d4140d7635cd31281a1bd90ea00548c2f06e30da3a249ad811cff
embedded_file_obj0019.bin pdf-embedded-file PDF EmbeddedFile object 19 at offset 0x8965 1697 bytes
SHA-256: d377a02f6815ef96ac0769c86d4b6abc59cfc99983d9e33001e3f30297bf51c0
embedded_file_obj0020.bin pdf-embedded-file PDF EmbeddedFile object 20 at offset 0x8C66 80 bytes
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
javascript_obj0040_000.js pdf-javascript-stream PDF /JS object 40 at offset 0x7DBCF 2795 bytes
SHA-256: 826c5622c798d67e5281cca7e05933dddc90ccdcb0a6177c9f7d06f11bef8f7f
Preview script
First 1,000 lines of the extracted script
if (typeof(this.ADBE) == "undefined")
   this.ADBE = new Object();
ADBE.LANGUAGE = "ENU";
ADBE.Viewer_string_Title = "Adobe Acrobat";
ADBE.Viewer_string_Update_Desc = "Adobe Interactive Forms Update";
ADBE.Viewer_string_Update_Reader_Desc = "Adobe Reader 7.0.5";
ADBE.Reader_string_Need_New_Version_Msg = "This PDF file requires a newer version of Adobe Reader. Press OK to download the latest version or see your system administrator.";
ADBE.Viewer_Form_string_Reader_601 = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator.";
ADBE.Viewer_Form_string_Reader_Older = "This PDF form requires a newer version of Adobe Reader. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK for online download information or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_601 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. Press OK to initiate an online update or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_60 = "This PDF form requires a newer version of Adobe Acrobat. Although the form may appear to work properly, some elements may function improperly or may not appear at all. For more information please copy the following URL (CTRL+C on Win, Command-C on Mac) and paste into your browser or see your system administrator.";
ADBE.Viewer_Form_string_Viewer_Older = "This PDF requires a newer version of Acrobat. Copy this URL and paste into your browser or see your sys admin.";
ADBE.Viewer_Form_string_Reader_5x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will open your browser to a web page where you can obtain the latest version.";
ADBE.Viewer_Form_string_Reader_6_7x = "This PDF form requires a newer version of Adobe Reader. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version.";
ADBE.Viewer_Form_string_Viewer = "This PDF form requires a newer version of Adobe Acrobat. Without a newer version, the form may be displayed, but it might not work properly. Some form elements might not be visible at all. If an internet connection is available, clicking OK will download and install the latest version.";
javascript_obj0041_001.js pdf-javascript-stream PDF /JS object 41 at offset 0x7DE94 902 bytes
SHA-256: 1b2ec98752b966f601d5223a750559cf13d562ac5e5c6d1fcc7217835b01f5fd
Preview script
First 1,000 lines of the extracted script
if (typeof(ADBE.Reader_Value_Asked) == "undefined")
   ADBE.Reader_Value_Asked = false;
if (typeof(ADBE.Viewer_Value_Asked) == "undefined")
   ADBE.Viewer_Value_Asked = false;
if (typeof(ADBE.Reader_Need_Version) == "undefined" || ADBE.Reader_Need_Version < 8.1)
{
   ADBE.Reader_Need_Version = 8.1;
   ADBE.Reader_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&r=" + ADBE.Reader_Need_Version;
}
if (typeof(ADBE.Viewer_Need_Version) == "undefined" || ADBE.Viewer_Need_Version < 8.1)
{
   ADBE.Viewer_Need_Version = 8.1;
   ADBE.Viewer_Value_New_Version_URL = "http://cgi.adobe.com/special/acrobat/update";
   ADBE.SYSINFO = "?p=" + app.platform + "&v=" + app.viewerVersion + "&l=" + app.language + "&c=" + app.viewerType + "&r=" + ADBE.Viewer_Need_Version;
}
javascript_obj0042_002.js pdf-javascript-stream PDF /JS object 42 at offset 0x7DFEC 1313 bytes
SHA-256: f94e41f586bf3f20bc1deeac4bfbda388a61db43f25fbd6304ba73f5653368cf
Preview script
First 1,000 lines of the extracted script
if (typeof(xfa_installed) == "undefined" || typeof(xfa_version) == "undefined" || xfa_version < 2.6)
{
   if (app.viewerType == "Reader")
   {
      if (ADBE.Reader_Value_Asked != true)
      {
         if (app.viewerVersion < 8.0)
         {
            if (app.alert(ADBE.Reader_string_Need_New_Version_Msg, 1, 1) == 1)
               this.getURL(ADBE.Reader_Value_New_Version_URL + ADBE.SYSINFO, false);
            ADBE.Reader_Value_Asked = true;
         }
         else if (app.alert(ADBE.Viewer_Form_string_Viewer, 1, 1) == 1)
            app.findComponent({cType:"Plugin", cName:"XFA", cVer:"2.6"});
      }
   }
   else
   {
      if (ADBE.Viewer_Value_Asked != true)
      {
         if (app.viewerVersion < 7.0)
            app.response({cQuestion: ADBE.Viewer_Form_string_Viewer_Older, cDefault: ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, cTitle: ADBE.Viewer_string_Title});
		   else if (app.viewerVersion < 8.0)
         {
            if (app.alert(ADBE.Viewer_Form_string_Viewer, 1, 1) == 1)
               app.launchURL(ADBE.Viewer_Value_New_Version_URL + ADBE.SYSINFO, true);
         }
         else if (app.alert(ADBE.Viewer_Form_string_Viewer, 1, 1) == 1)
            app.findComponent({cType:"Plugin", cName:"XFA", cVer:"2.6"});
         ADBE.Viewer_Value_Asked = true;
      }
   }
}
xfa_image_rawvalue_000.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x6D67 17350 bytes
SHA-256: ca9594e5acb74fd54230c1f0e6d1ea53619d226882e1be98d1ea6e6bb4a09f48
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.76, consistent with packed or encrypted content.
stream_011_off00009b7d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9B7D 352198 bytes
SHA-256: 1e8564d3d89047875dccaa98279599de9d7ddf77240906041f1156ba8edf3315
stream_012_off0003b11a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3B11A 367087 bytes
SHA-256: b8e2518b116c26bab0e9f8c1672daf405dedad561157502b657e9005be2029aa
font_01_sfnt_off0006d932.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6D932 95975 bytes
SHA-256: c29e5b1537bee8c88b3ffca56c5f24a45ec8da374cf9d4c0b4a78d04fc230949
embedded_file_obj0001_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 1 at offset 0xEF1; filter decode failed 176 bytes
SHA-256: e75bcc5bf78a4d2c13247e95fd2ee612e31c2d599e604d23f4b5ca0aa8f6c0ab
embedded_file_obj0002_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 2 at offset 0xFFA; filter decode failed 912 bytes
SHA-256: 675a8f3918d27c703c6e5fa345d09994b30c0331c7a89ec66876f3a490b8a1c6
embedded_file_obj0003_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 3 at offset 0x13E5; filter decode failed 24096 bytes
SHA-256: 8788fb1c5cdd26a171cd2df52e2356dee6756731f3b878d19d2f5f9ddf73fbac
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
embedded_file_obj0004_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 4 at offset 0x725E; filter decode failed 832 bytes
SHA-256: bf4eab06a80bcc24ef0c6467885b95ae6dbb138239f7e04fa53f4f80d32f2e82
embedded_file_obj0005_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 5 at offset 0x75F7; filter decode failed 256 bytes
SHA-256: 05911866a5fa26aa2d486ef0845b81fe662a153cf18e1f2f861d1ec4c0f4644d
embedded_file_obj0006_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 6 at offset 0x7750; filter decode failed 128 bytes
SHA-256: 706efaacf314b504560a4249983a211d8f3ea0fa4b31ae3ebeaf9a93fe036038
embedded_file_obj0007_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 7 at offset 0x7829; filter decode failed 176 bytes
SHA-256: 410c9e299fcf8aa1a8ccd6e1a8e83570b0c49be7425512d5245d60db4ebf5141
embedded_file_obj0008_undecoded.bin pdf-embedded-file-undecodable PDF EmbeddedFile object 8 at offset 0x7932; filter decode failed 704 bytes
SHA-256: 4257b15f4484e55ce3952c84a5039ae1c3bdaf1bf848683b98dd5c1797c1fa85