Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7979169b2f21a42…

MALICIOUS

PDF

70.1 KB Created: ÜÐ037ß)G034BG§&±x¾æÂ…‘†Ëô.s First seen: 2026-05-10
MD5: 0fec6bd1eefb1b170d68169d394e577a SHA-1: d249137b8e4d950b2c8853a18c804231db0d6455 SHA-256: b7979169b2f21a422a18aaa5a770216b52bcd84dc044525bb8311a27b78e9e1d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information

The PDF file is encrypted and contains embedded JavaScript, indicating an attempt to conceal malicious activity. The heuristic 'PDF_ENCRYPTED_WITH_JS' strongly suggests that the JavaScript is used to bypass static analysis and potentially deliver a malicious payload. The embedded URL 'http://www.cadkas.com' is likely part of the lure or infrastructure. The presence of JavaScript actions and streams points to an obfuscated execution flow, common in phishing or credential theft attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 6

  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.cadkas.com In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0020_000.js pdf-javascript-stream PDF /JS object 20 at offset 0x69F8 46 bytes
SHA-256: d3b3619843a9765d54ecc0d81f8728e633434bc486e3888d07256848d199d3df
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s).
Preview script
First 1,000 lines of the extracted script
eval('eval("'+this.getField("e").value+'");');
javascript_obj0021_000.js pdf-javascript-stream PDF /JS object 21 at offset 0x1847 46 bytes
SHA-256: 11dd3dd5217a269b6e477c77d269b1bf182a5c6d0f312ad5b43892728b614d88
Preview script
First 1,000 lines of the extracted script
x�h��W�ۣ� y�
 `�]���ӎg_u��� v � j�T[�7ا�R��