MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.001 Spearphishing Attachment
T1204.002 Malicious File
The PDF file exhibits multiple indicators of malicious intent, including embedded JavaScript streams and embedded script payloads. The presence of XFA forms and AcroForm buttons suggests an attempt to create an interactive lure. The embedded JavaScript, specifically javascript_obj0133_000.js and javascript_obj0134_001.js, is the primary mechanism for executing malicious code, likely downloading and executing a second-stage payload. The document body was not parsable, limiting further analysis of the lure.
Heuristics 8
-
Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/mm/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xfa/promoted-desc/
Extracted artifacts 14
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0006.bin51886c02f18523c864de9517a248d92d526ae6888aaed7586d0f989b0fa381e8 |
pdf-embedded-file | PDF EmbeddedFile object 6 at offset 0x4B03 | 163 bytes |
embedded_file_obj0007.bin267bc6bcdb8ed6e633f25fa68791bd9ceeb332247a849a3e3bfeee63b6d55c90 |
pdf-embedded-file | PDF EmbeddedFile object 7 at offset 0x4BF2 | 2405 bytes |
embedded_file_obj0008.bin08cae221857a208d72230ddb7c80fec725beeff56378b5f3454acfed9f8738b1 |
pdf-embedded-file | PDF EmbeddedFile object 8 at offset 0x4FE4 | 2921 bytes |
embedded_file_obj0009.bin1715982188cf22e2877bd76c2a70243d16c113fc64cc0c8020610ce5644399c8 |
pdf-embedded-file | PDF EmbeddedFile object 9 at offset 0x5388 | 1535 bytes |
embedded_file_obj0010.bin2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19 |
pdf-embedded-file | PDF EmbeddedFile object 10 at offset 0x5647 | 80 bytes |
embedded_file_obj0011.bin4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1 |
pdf-embedded-file | PDF EmbeddedFile object 11 at offset 0x56EF | 56 bytes |
javascript_obj0133_000.js529357503ec67b623d2a12816cdeea62bd639f2b4ff4e568b01c96cc3f5bfc6f |
pdf-javascript-stream | PDF /JS object 133 at offset 0x7139 | 1363 bytes |
javascript_obj0134_001.jse985b5df65c8c3cf732a9074b575fbc594c1c7f0bccc0994182ec7e5c0f7308a |
pdf-javascript-stream | PDF /JS object 134 at offset 0x7315 | 902 bytes |
javascript_obj0135_002.js0ab3d232b2f2272b7039ee3e45d0be78ade06bb45327a799559ad4a592ef5a3d |
pdf-javascript-stream | PDF /JS object 135 at offset 0x746E | 1169 bytes |
stream_001_off000001da.js26218a59363e858154224edbe3b445f354c4f341aa36b2291598a74c6c570668 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1DA | 68830 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 3 long base64-like blob(s).
|
|||
stream_002_off000039b3.bin96f3b95ac590a24927aef9abf434358866dbefb8e8fe69b77b4b3dbd0e90e048 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x39B3 | 856 bytes |
font_00_sfnt_off00007f1e.bin1626e6329f65d0d35cdf751ec668ac4b8800d726707d01e7810bb8297d789dee |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7F1E | 94351 bytes |
font_01_cff_off00019727.bin77a0b6c3eea44eabe1eca27c9a3556172dbbac4102a91eebaaca2ab4e62f2f25 |
pdf-font-stream | PDF embedded font (cff) at offset 0x19727 | 5600 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.42, consistent with packed or encrypted content.
|
|||
font_02_cff_off0001ad79.bin19164b1e8011f1baf8fcc59c104786acda8c6d3aadd1a7e0607059d9baecca17 |
pdf-font-stream | PDF embedded font (cff) at offset 0x1AD79 | 3195 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.