Malicious PDF — malware analysis report

Static analysis result for SHA-256 b54996bc7897a49a…

MALICIOUS

PDF

6.4 KB First seen: 2026-05-11
MD5: c86573e81d495ec753ad07d140ee1b84 SHA-1: 625471582ec1a3dc2196f2cf9171471a6745db88 SHA-256: b54996bc7897a49a382a2cd14fcbe2f01df4eade38c30fb67de19c31cca75269
148 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 JavaScript/JScript

The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The script utilizes the unescape() function, a common technique for obfuscating malicious code within PDF documents. While no specific exploit is identified, the presence of obfuscated JavaScript suggests an attempt to leverage PDF vulnerabilities for malicious purposes. The benign URLs present do not indicate malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9833

Heuristics 4

  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
    function RandomVar8(RandomVar9){return unescape(RandomVar9.replace(/ARG/g,a));}
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objstm_0024_00.bin pdf-objstm-decoded PDF /ObjStm 24 0 obj (inflated) 456 bytes
SHA-256: 648756dcbbd08f8f0d765e3cbaa8a23556566d274443755dcda1464ef0d3ccec