PDF static analysis report

Static analysis result for SHA-256 def2178dd4c1f182…

SUSPICIOUS

PDF

463.7 KB First seen: 2026-05-10
MD5: 8391bbe9c9e873b0e914b8f7e02bb517 SHA-1: e2add5bafae4c39d38e2e3d5b31ffdd5638d5aa9 SHA-256: def2178dd4c1f182615dc08af3e82cff92c43a9f0f32ef7b38cac86e69f4a3ca
38 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

The PDF file exhibits multiple indicators of malicious intent, including embedded JavaScript and embedded script payloads. The presence of these elements strongly suggests an attempt to execute arbitrary code. Specifically, the embedded JavaScript action and the embedded script payload heuristic indicate that the document is designed to download and run a secondary payload. The embedded files, particularly 'embedded_file_obj0003.bin' and 'embedded_file_obj0007.bin', are likely components of this malicious chain.

Machine Learning

  • Nyx PDF Classifier clean score 0.0594

Heuristics 7

  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded script payload in PDF stream info PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ocsp.verisign.com0 Referenced by PDF JavaScript
    • http://www.monotype.comMonotypeReferenced by PDF JavaScript
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/mm/Referenced by PDF JavaScript
    • http://purl.org/dc/elements/1.1/Referenced by PDF JavaScript
    • http://ns.adobe.com/pdf/1.3/Referenced by PDF JavaScript
    • http://ns.adobe.com/xfa/promoted-desc/Referenced by PDF JavaScript
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://crl.verisign.com/tss-ca.crl0Referenced by PDF JavaScript
    • http://crl.verisign.com/ThawteTimestampingCA.crl0Referenced by PDF JavaScript
    • https://www.verisign.com/rpaReferenced by PDF JavaScript
    • https://www.verisign.com/rpa01Referenced by PDF JavaScript
    • http://crl.verisign.com/pca3.crl0Referenced by PDF JavaScript
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DReferenced by PDF JavaScript
    • https://www.verisign.com/rpa0Referenced by PDF JavaScript
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0Referenced by PDF JavaScript
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/2.8/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.5/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-connection-set/2.1/Referenced by PDF JavaScript
    • http://ns.adobe.com/data-description/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.1/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
    • http://ocsp.verisign.com/ocsp/status0Referenced by PDF JavaScript
    • http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl0Referenced by PDF JavaScript
    • http://www.microsoft.com/typographyReferenced by PDF JavaScript
    • http://www.monotype.com/html/mtname/ms_timesnewroman.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlReferenced by PDF JavaScript
    • http://www.w3.org/2001/XMLSchemaIn PDF document text
    • http://ns.adobe.com/xfdf/In PDF document text

Extracted artifacts 16

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x2A0F3 86 bytes
SHA-256: f7ee3ef2f8f35d669a6c2b8b0b0ee89655bbc3d04b107a8d22531830f6fc28a1
embedded_file_obj0002.bin pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x2A1A6 1948 bytes
SHA-256: adad585985b0d04a4b2756f5b7ae05e9503e5a28517161c939dbe0a3f6c373c6
embedded_file_obj0003.bin pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x2A500 88921 bytes
SHA-256: 12ca6ca3c28a41d42a30909740757a3b6975ca8a35631f00d5b58977d367ad14
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
embedded_file_obj0004.bin pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x2E6E8 247 bytes
SHA-256: 24146e4db419bb5c999ccad5235b221a937cd6b0e052baf71198bc69ffa7f3c5
embedded_file_obj0005.bin pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x2E7EB 7785 bytes
SHA-256: 7bbd73afb3d3a0556394d022545292f3404fe903732bf8f7629f7d226dab5ec7
embedded_file_obj0006.bin pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x2EBB6 2423 bytes
SHA-256: 2d58413fda1ff20c994606823bf49e41194612c0137b6315e50fa7bdc01f1e09
embedded_file_obj0007.bin pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x2EE99 536032 bytes
SHA-256: 5e095595962226db385daec26b75f9ba919e441b846487ab1d661e16e3e4ebba
embedded_file_obj0008.bin pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x3714A 1837 bytes
SHA-256: d0c1a2319f8a118dddd777a3f26b5855d47ffb873bf09c5467371f472075a954
embedded_file_obj0009.bin pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x37463 80 bytes
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
embedded_file_obj0010.bin pdf-embedded-file PDF EmbeddedFile object 10 at offset 0x3750E 4824 bytes
SHA-256: 7e23ec00c2986fdf12ffb8a7d56b57c20f19ebc3b5fd74c8e6d4771fd788e37c
stream_002_off000006e8.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6E8 1532 bytes
SHA-256: f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8
stream_003_off000008d3.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8D3 870 bytes
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
stream_110_off000377e5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x377E5 409252 bytes
SHA-256: a0f5b5f69a88877ffaa1733f0e0bbf9b4b3eef82f4ff804c724870cecea228d2
objstm_0072_00.bin pdf-objstm-decoded PDF /ObjStm 72 0 obj (inflated) 31908 bytes
SHA-256: 0467769c2333ad3ef0e3eb0f1ccd891fcc722eedf08c4ee74814ce12c162a652
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 12 long base64-like blob(s).
font_00_sfnt_off00000f91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF91 95975 bytes
SHA-256: c29e5b1537bee8c88b3ffca56c5f24a45ec8da374cf9d4c0b4a78d04fc230949
font_01_sfnt_off000115d7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x115D7 97320 bytes
SHA-256: 926d8eb5abd4c74e46a419aaf25a490564d389c7a250d2392b198a342df65b8a