MALICIOUS
106
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious File
The PDF file exhibits multiple suspicious findings, including embedded JavaScript and multiple embedded PDF files. One embedded PDF child was flagged with a high score due to multiple PDF_XREF_OFFSET_MISMATCH errors, indicating potential obfuscation or corruption. The presence of embedded files and JavaScript suggests an attempt to deliver a secondary payload or exploit vulnerabilities. The file is likely a dropper or exploit container.
Heuristics 7
-
Embedded PDF child has suspicious static findings critical PDF_EMBEDDED_CHILD_STATIC_TRIAGEPDF contains an embedded PDF stream whose extracted child matches suspicious or malicious PDF heuristics. Wrapper PDFs are commonly used to hide the actual exploit or lure payload from scanners that do not recursively inspect attachments.
-
PDF paints image(s) but contains no text operators medium PDF_IMAGE_ONLY_LUREPDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/mm/
Extracted artifacts 23
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
c993d.pdf1da31f2da0eb50631fc41c9247c56a219656035be1ae869b1860ca2ec00db61d |
pdf-embedded-file | PDF EmbeddedFile object 2 at offset 0x1F480 | 22610 bytes |
d13744.pdfac5edbb87525d2f915fdc932a53ddd534e587789ae3fceec86f9c67a2ef3905d |
pdf-embedded-file | PDF EmbeddedFile object 12 at offset 0x29EBA | 78126 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 15 long base64-like blob(s).
|
|||
d13812.pdf1e2de5e89a69da3eaae116c2a847ba3a3318c665753305af9e73ed4ee02722ce |
pdf-embedded-file | PDF EmbeddedFile object 13 at offset 0x2F109 | 77926 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 11 long base64-like blob(s).
|
|||
d13915.pdfd108f7d742191a37a6d1b13145b51f2258e088bc4f19cd2fae7cef937ccf253d |
pdf-embedded-file | PDF EmbeddedFile object 15 at offset 0x39A1F | 43771 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 27 long base64-like blob(s).
|
|||
d14402.pdfa74179a36b051f1d73e70dc9f729ff0233ab464367c2912475030d20f56ac8ea |
pdf-embedded-file | PDF EmbeddedFile object 17 at offset 0x45BC3 | 25354 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 8 long base64-like blob(s).
|
|||
c997c.pdf52e1336eb9f8d976c45abaee8802ba5be233867120195d048ccaa1ce238f535f |
pdf-embedded-file | PDF EmbeddedFile object 3 at offset 0x4C453 | 22420 bytes |
d13220.pdf173730b84ad71290f57c037f6ded3853c0444d6909ee06e103b66d53f6018386 |
pdf-embedded-file | PDF EmbeddedFile object 11 at offset 0x51ADB | 79469 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 60 long base64-like blob(s).
|
|||
d13855.pdfa40908cec89816d34cc72f7587717b0dae9426aa0a349246ec67f4778b5d8054 |
pdf-embedded-file | PDF EmbeddedFile object 14 at offset 0x6149A | 76766 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 34 long base64-like blob(s).
|
|||
d14401.pdf26d5ee1066fd08bbc4d81f556fd7cb495700cf57a93bdea9c329e449a35d555f |
pdf-embedded-file | PDF EmbeddedFile object 16 at offset 0x6C849 | 13364 bytes |
d12271.pdf23da8f446753bca4573fcb9360300be4b804d10e18d7ce4e2b1920b0d66b6d34 |
pdf-embedded-file | PDF EmbeddedFile object 4 at offset 0x79758 | 32482 bytes |
d12391.pdf278d6f8e8ef4569935c6836d176dfc3ca2b0867105df94fd4fcc4835ab18c2b5 |
pdf-embedded-file | PDF EmbeddedFile object 5 at offset 0x8095D | 7619 bytes |
d13203.pdf1272b1af80709286f88b1dba3bda02de350a70501dfd11f7bfb6ef28e0fd7ffa |
pdf-embedded-file | PDF EmbeddedFile object 6 at offset 0x8F303 | 6932 bytes |
d13216.pdffd1070305b85bfb63c26c617752ce2e2bc783983166f3cebb71f35439c0d7ef5 |
pdf-embedded-file | PDF EmbeddedFile object 7 at offset 0x9C822 | 7987 bytes |
d13217.pdf853019c2989d61317dda3b1acca7390137a6b029f162bf20218d74c6755023ce |
pdf-embedded-file | PDF EmbeddedFile object 8 at offset 0xAB2BB | 7855 bytes |
d13218.pdf7d81c311b546441e0bec7d78133351837d5fdb2996282db0e0c0b90f69c7ad78 |
pdf-embedded-file | PDF EmbeddedFile object 9 at offset 0xB989B | 28113 bytes |
d13219.pdf73e7b6554975f1736c90bcc3d92d83e130dc5bfa639bba3664decd77c8d324c2 |
pdf-embedded-file | PDF EmbeddedFile object 10 at offset 0xBF942 | 5424 bytes |
d14403.pdf58b9fcb5491623b1875ef973c7b95ef9e55c77c461ed761dbd87cf8d9cf648e7 |
pdf-embedded-file | PDF EmbeddedFile object 18 at offset 0x11DCDF | 6687 bytes |
d14404.pdfe020548763cd11c25e8e900e8cb31f93cea080b09aef03acc32d6ab673f18118 |
pdf-embedded-file | PDF EmbeddedFile object 19 at offset 0x12A9FC | 6228 bytes |
d9414.pdfba61161bd4ed8f92bdcfe653f2ce400633ee2e566cb7dbbd938480407cdd2f62 |
pdf-embedded-file | PDF EmbeddedFile object 20 at offset 0x1363C6 | 5589 bytes |
d9843.pdf49da57cb951758d5d17dbbf3eaa69bcb0eade03fc28ae59b7e9f5efefeed2ac4 |
pdf-embedded-file | PDF EmbeddedFile object 21 at offset 0x140020 | 9097 bytes |
javascript_obj0085_000.js97e6c8fb70f6fedab160a41095c99dce3c9d53a0086d3a8d4e6d47cbe03dce61 |
pdf-javascript-stream | PDF /JS object 85 at offset 0x61D | 1946 bytes |
stream_072_off0010df28.bin97f94a1cb585b77a49387474256cef2e611ecdad0222229bb00ff94c060aa1b0 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x10DF28 | 9522 bytes |
icc_00_off0001e6ef.icc2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
pdf-icc-profile | PDF ICC profile at offset 0x1E6EF | 3144 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.