SUSPICIOUS
38
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious File
The PDF file exhibits multiple indicators of malicious intent, including embedded JavaScript and embedded script payloads. The presence of these elements strongly suggests an attempt to execute arbitrary code. Specifically, the embedded JavaScript action and the embedded script payload heuristic indicate that the document is designed to download and run a secondary payload. The embedded files, particularly 'embedded_file_obj0003.bin' and 'embedded_file_obj0007.bin', are likely components of this malicious chain.
Machine Learning
- Nyx PDF Classifier clean score 0.0594
Heuristics 7
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded script payload in PDF stream info PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://ocsp.verisign.com0 Referenced by PDF JavaScript
- http://www.monotype.comMonotypeReferenced by PDF JavaScript
- http://www.w3.org/1999/02/22-rdf-syntax-ns#Referenced by PDF JavaScript
- http://ns.adobe.com/xap/1.0/Referenced by PDF JavaScript
- http://ns.adobe.com/xap/1.0/mm/Referenced by PDF JavaScript
- http://purl.org/dc/elements/1.1/Referenced by PDF JavaScript
- http://ns.adobe.com/pdf/1.3/Referenced by PDF JavaScript
- http://ns.adobe.com/xfa/promoted-desc/Referenced by PDF JavaScript
- http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
- http://crl.verisign.com/tss-ca.crl0Referenced by PDF JavaScript
- http://crl.verisign.com/ThawteTimestampingCA.crl0Referenced by PDF JavaScript
- https://www.verisign.com/rpaReferenced by PDF JavaScript
- https://www.verisign.com/rpa01Referenced by PDF JavaScript
- http://crl.verisign.com/pca3.crl0Referenced by PDF JavaScript
- http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DReferenced by PDF JavaScript
- https://www.verisign.com/rpa0Referenced by PDF JavaScript
- http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0Referenced by PDF JavaScript
- http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlReferenced by PDF JavaScript
- http://ns.adobe.com/xdp/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xci/1.0/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xci/2.8/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-template/2.5/Referenced by PDF JavaScript
- http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-connection-set/2.1/Referenced by PDF JavaScript
- http://ns.adobe.com/data-description/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-locale-set/2.1/Referenced by PDF JavaScript
- http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
- http://ocsp.verisign.com/ocsp/status0Referenced by PDF JavaScript
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl0Referenced by PDF JavaScript
- http://www.microsoft.com/typographyReferenced by PDF JavaScript
- http://www.monotype.com/html/mtname/ms_timesnewroman.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlReferenced by PDF JavaScript
- http://www.w3.org/2001/XMLSchemaIn PDF document text
- http://ns.adobe.com/xfdf/In PDF document text
Extracted artifacts 16
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0001.bin |
pdf-embedded-file | PDF EmbeddedFile object 1 at offset 0x2A0F3 | 86 bytes |
SHA-256: f7ee3ef2f8f35d669a6c2b8b0b0ee89655bbc3d04b107a8d22531830f6fc28a1 |
|||
embedded_file_obj0002.bin |
pdf-embedded-file | PDF EmbeddedFile object 2 at offset 0x2A1A6 | 1948 bytes |
SHA-256: adad585985b0d04a4b2756f5b7ae05e9503e5a28517161c939dbe0a3f6c373c6 |
|||
embedded_file_obj0003.bin |
pdf-embedded-file | PDF EmbeddedFile object 3 at offset 0x2A500 | 88921 bytes |
SHA-256: 12ca6ca3c28a41d42a30909740757a3b6975ca8a35631f00d5b58977d367ad14 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 long base64-like blob(s).
|
|||
embedded_file_obj0004.bin |
pdf-embedded-file | PDF EmbeddedFile object 4 at offset 0x2E6E8 | 247 bytes |
SHA-256: 24146e4db419bb5c999ccad5235b221a937cd6b0e052baf71198bc69ffa7f3c5 |
|||
embedded_file_obj0005.bin |
pdf-embedded-file | PDF EmbeddedFile object 5 at offset 0x2E7EB | 7785 bytes |
SHA-256: 7bbd73afb3d3a0556394d022545292f3404fe903732bf8f7629f7d226dab5ec7 |
|||
embedded_file_obj0006.bin |
pdf-embedded-file | PDF EmbeddedFile object 6 at offset 0x2EBB6 | 2423 bytes |
SHA-256: 2d58413fda1ff20c994606823bf49e41194612c0137b6315e50fa7bdc01f1e09 |
|||
embedded_file_obj0007.bin |
pdf-embedded-file | PDF EmbeddedFile object 7 at offset 0x2EE99 | 536032 bytes |
SHA-256: 5e095595962226db385daec26b75f9ba919e441b846487ab1d661e16e3e4ebba |
|||
embedded_file_obj0008.bin |
pdf-embedded-file | PDF EmbeddedFile object 8 at offset 0x3714A | 1837 bytes |
SHA-256: d0c1a2319f8a118dddd777a3f26b5855d47ffb873bf09c5467371f472075a954 |
|||
embedded_file_obj0009.bin |
pdf-embedded-file | PDF EmbeddedFile object 9 at offset 0x37463 | 80 bytes |
SHA-256: 2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19 |
|||
embedded_file_obj0010.bin |
pdf-embedded-file | PDF EmbeddedFile object 10 at offset 0x3750E | 4824 bytes |
SHA-256: 7e23ec00c2986fdf12ffb8a7d56b57c20f19ebc3b5fd74c8e6d4771fd788e37c |
|||
stream_002_off000006e8.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x6E8 | 1532 bytes |
SHA-256: f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8 |
|||
stream_003_off000008d3.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x8D3 | 870 bytes |
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb |
|||
stream_110_off000377e5.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x377E5 | 409252 bytes |
SHA-256: a0f5b5f69a88877ffaa1733f0e0bbf9b4b3eef82f4ff804c724870cecea228d2 |
|||
objstm_0072_00.bin |
pdf-objstm-decoded | PDF /ObjStm 72 0 obj (inflated) | 31908 bytes |
SHA-256: 0467769c2333ad3ef0e3eb0f1ccd891fcc722eedf08c4ee74814ce12c162a652 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 12 long base64-like blob(s).
|
|||
font_00_sfnt_off00000f91.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF91 | 95975 bytes |
SHA-256: c29e5b1537bee8c88b3ffca56c5f24a45ec8da374cf9d4c0b4a78d04fc230949 |
|||
font_01_sfnt_off000115d7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x115D7 | 97320 bytes |
SHA-256: 926d8eb5abd4c74e46a419aaf25a490564d389c7a250d2392b198a342df65b8a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.