Malicious PDF — malware analysis report

Static analysis result for SHA-256 ecae45737997d8fd…

MALICIOUS

PDF

1.40 MB First seen: 2026-05-11
MD5: be723e3c4616e09c57803898ae99b0bb SHA-1: 4e1a6ee3d432b124ec1b9a7ede6b96da40139050 SHA-256: ecae45737997d8fd9bdc845c0791dc802ed4d373514deb060670c5988071429a
248 Risk Score

🔏 Digital signature Signed

A signature covers the whole signed byte range — PDF JavaScript is never signed on its own — and does not by itself mean the document is safe.

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious File

This PDF file exhibits malicious behavior through the use of XFA forms and embedded JavaScript. The embedded JavaScript stream, particularly 'stream_002_off00000504.js', contains eval() calls and prototype pollution patterns, indicating it's designed to deobfuscate and execute further malicious code. This strongly suggests the document's primary purpose is to act as a downloader for a second-stage payload, leveraging the embedded scripts to achieve this. The presence of multiple heuristic firings related to JavaScript and embedded payloads supports this assessment.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.2506

Heuristics 9

  • JavaScript action low 4 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Prototype-pollution JavaScript pattern high CVE related PDF_JS_PROTOTYPE_POLLUTION
    PDF JavaScript mutates object prototypes while also referencing privileged or sensitive PDF APIs. This tracks a modern PDF exploit technique family without assigning an unverified CVE.
  • exportDataObject + nLaunch — embedded-file launch-on-open dropper critical PDF_JS_EXPORT_LAUNCH_DROPPER
    PDF JavaScript calls exportDataObject() with nLaunch set, which extracts the document's embedded file and launches it in its default application. This is a launch-on-open dropper: the embedded file is the payload. No benign workflow auto-launches an extracted PDF attachment. (identified after nested-decoder de-obfuscation)
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
       var node = list.item(i);
       el.addItem(eval(node[label]).value, eval(node[val]).value);
      }
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://s-eacea-web1dev.net1.cec.eu.int/WSXMLReceiverAx1/services/WSXMLReceiverAx1 Referenced by PDF JavaScript
    • http://ocsp.verisign.com0Referenced by PDF JavaScript
    • http://www.monotype.comMonotypeReferenced by PDF JavaScript
    • http://wlsdev2.cc.cec.eu.int:7021/xmlgate/services/XmlgateServiceIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/Referenced by PDF JavaScript
    • http://ns.adobe.com/pdf/1.3/Referenced by PDF JavaScript
    • http://ns.adobe.com/xap/1.0/mm/Referenced by PDF JavaScript
    • http://purl.org/dc/elements/1.1/Referenced by PDF JavaScript
    • http://ns.adobe.com/xfa/promoted-desc/Referenced by PDF JavaScript
    • http://ns.adobe.com/xdp/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xci/2.8/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.8/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://eacea.ec.europa.euReferenced by PDF JavaScript
    • http://eacea.ec.europa.eu/eforms/index_en.phpReferenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.7/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.6/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
    • http://ns.adobe.com/data-description/Referenced by PDF JavaScript
    • http://eacea.ec.europa.eu/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-connection-set/2.8/Referenced by PDF JavaScript
    • http://eacea.ec.europa.eu/WSXMLReceiverAx1P/services/WSXMLReceiverAx1Referenced by PDF JavaScript
    • http://www.w3.org/2000/01/rdf-schema#Referenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Referenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/ATReferenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/BEReferenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/BGReferenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/CYReferenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/CZReferenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/DKReferenced by PDF JavaScript
    • https://sanco.ec.europa.eu/RDF/Country/EEReferenced by PDF JavaScript
    • http://www.w3.org/2001/XMLSchemaReferenced by PDF JavaScript
    • http://www.w3.org/2002/01/xformsReferenced by PDF JavaScript
    • http://crl.verisign.com/tss-ca.crl0Referenced by PDF JavaScript
    • http://crl.verisign.com/ThawteTimestampingCA.crl0Referenced by PDF JavaScript
    • https://www.verisign.com/rpaReferenced by PDF JavaScript
    • https://www.verisign.com/rpa01Referenced by PDF JavaScript
    • http://crl.verisign.com/pca3.crl0Referenced by PDF JavaScript
    • http://CSC3-2004-crl.verisign.com/CSC3-2004.crl0DReferenced by PDF JavaScript
    • https://www.verisign.com/rpa0Referenced by PDF JavaScript
    • http://CSC3-2004-aia.verisign.com/CSC3-2004-aia.cer0Referenced by PDF JavaScript
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlReferenced by PDF JavaScript
    • http://www.adobe.com/typehttp://www.adobe.com/type/legal.htmlMyriadReferenced by PDF JavaScript
    • https://www.verisign.com/repository/CPSReferenced by PDF JavaScript
    • https://www.verisign.comReferenced by PDF JavaScript
    • https://www.verisign.com/repository/verisignlogo.gif0Referenced by PDF JavaScript
    • https://www.verisign.com/CPS0bReferenced by PDF JavaScript
    • http://www.microsoft.com/truetype/0Referenced by PDF JavaScript
    +33 more URL(s)

Extracted artifacts 19

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_001_off00000126.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x126 2429 bytes
SHA-256: a3df82428e2800391b244eab74ddd0a0d790898d8469f9b0f1e42a9a71a0f1bd
stream_002_off00000504.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x504 1019081 bytes
SHA-256: e4d612c928dc365787907f541f8dad02689a87929c98ab2ad8699e8e0ed67511
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 eval/decoder/string-building token(s). Carved artifact contains 4 long base64-like blob(s).
stream_003_off000361d4.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x361D4 5711 bytes
SHA-256: b16a77f36a1dbb10b68158d5bc3bc5894c1696984d4fcfb18db002aa5ca6cb65
stream_004_off0003664f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3664F 47559 bytes
SHA-256: cac9c34aeab80f505296f22cac62dc239a5cea1ffae6361d1991c279d415fadb
stream_005_off00037614.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x37614 8178 bytes
SHA-256: 8ed9cdaaef2aa769579a4ba835e39256b1c3971f55aa85f7b7c268d675cc53f7
stream_006_off00037d70.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x37D70 374 bytes
SHA-256: 82883b1c356644ec1217b1e20b594e85f02d0657b4324c7bfe032e52e5e13b8e
stream_008_off00039d5c.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x39D5C 895200 bytes
SHA-256: 04d0c9976d81c8ac08186397a6e1b0eda7a6896713d9d7591343b1b07999ec47
stream_016_off0008c2d7.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8C2D7 102219 bytes
SHA-256: b2a50460b1fc66b7680230c728241859435e1af538bd15e880282e123198de62
stream_017_off0009dc50.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9DC50 188972 bytes
SHA-256: f13c106e4ee427254e92d68485d1420403c9e874eee0f33787ff10fe62f8018f
stream_018_off000bd89f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xBD89F 196605 bytes
SHA-256: 55cb4b903a99e15bba7a1da6ca466776cafcadab161604e20e685e4472952dcf
stream_019_off000dea3d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0xDEA3D 367087 bytes
SHA-256: b8e2518b116c26bab0e9f8c1672daf405dedad561157502b657e9005be2029aa
stream_021_off001300e2.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1300E2 352198 bytes
SHA-256: 1e8564d3d89047875dccaa98279599de9d7ddf77240906041f1156ba8edf3315
stream_023_off00163e8b.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x163E8B 1367 bytes
SHA-256: f8721569904600df33f536ddc9f4942717077f9d6c3c4253a8f4de5650fc6531
stream_024_off00164074.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x164074 902 bytes
SHA-256: 91ea259764c68d27b8981a339c02d8ea92224ae5c0d0cd0a7c8f3d645d599090
objstm_0024_00.bin pdf-objstm-decoded PDF /ObjStm 24 0 obj (inflated) 23672 bytes
SHA-256: e2a3d05f1d0df61c6cbe50ca6bcc777ed2035cb0b7207d78d7b94e30244959e4
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 5 long base64-like blob(s).
font_00_sfnt_off00048bf5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48BF5 95975 bytes
SHA-256: c29e5b1537bee8c88b3ffca56c5f24a45ec8da374cf9d4c0b4a78d04fc230949
font_01_sfnt_off00058edf.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x58EDF 99778 bytes
SHA-256: 4f8a962143becce891b0f8d40b5315e54e2a298ba661302850ebd34e48af909a
font_02_sfnt_off0006a19f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6A19F 102071 bytes
SHA-256: b1260c85fef77007b5f19c1c6f3552e1c6ade6c959082cf86dd6971951ed119c
font_03_sfnt_off0007bbbc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7BBBC 97320 bytes
SHA-256: 926d8eb5abd4c74e46a419aaf25a490564d389c7a250d2392b198a342df65b8a