Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe7e00f9e01387c9…

MALICIOUS

PDF

536.5 KB Created: xu´DT0!KnÒ625ÿǐ Authoring application: lå _t,U9b&W©Œ¹¾ÆHìu (via },ôNt9?4zom ›¸÷œ êE÷WZE) First seen: 2026-05-08
MD5: 648159d049e17c46931d52597f4edb39 SHA-1: a3098bf491cf4daecdd42a92f975cf4084702366 SHA-256: fe7e00f9e01387c9344c350c68c64cdcc23bd34cfdc57ac13e607c256c2f0c42
118 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF file is encrypted and contains JavaScript, indicating an attempt to conceal its true content and behavior. The presence of JavaScript actions and embedded JS streams suggests that the script is responsible for decrypting or executing the malicious payload. The PDF_IMAGE_ONLY_LURE heuristic suggests the document may be designed to trick users into interacting with it, possibly by presenting an image that requires further action. The combination of encryption and JavaScript points to a downloader or dropper mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9305

Heuristics 7

  • Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JS
    PDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • JavaScript action low 1 related finding PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • AcroForm button with action trigger low PDF_ACROFORM_BUTTON
    PDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.monotype.comhttp://www.monotype.com/html/type/license.html In PDF document text
    • http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATIONIn PDF document text
    • http://www.iec.chIn PDF document text
🗂 Part of campaign: shared payload 47a4c5a45e 3 samples

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0240_001.js pdf-javascript-stream PDF /JS object 240 at offset 0x125B9 33 bytes
SHA-256: f0a0eef79d820433b6742ba4c20f8407e0f3f78f2a827bda377f7690ca7578a1
Preview script
First 1,000 lines of the extracted script
AFDate_KeystrokeEx("mm-dd-yyyy");
stream_086_off00024c66.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x24C66 5832 bytes
SHA-256: 6cd6ccca5f401625bd8008aa506e350166d01a25a2a6041c290aecd55ca66e70
stream_088_off00027368.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x27368 224990 bytes
SHA-256: 47a4c5a45ebac005bd0066b3744f43dc55580d11b7befe7356e010c61617aa11
icc_00_off00063ab2.icc pdf-icc-profile PDF ICC profile at offset 0x63AB2 3144 bytes
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e
font_00_cff_off00065e4d.bin pdf-font-stream PDF embedded font (cff) at offset 0x65E4D 465 bytes
SHA-256: b2491543cd4dd3553cea63d439630a911d7677b34f488114c7c920379870962d
font_01_cff_off0006604a.bin pdf-font-stream PDF embedded font (cff) at offset 0x6604A 478 bytes
SHA-256: 27549493b0b24d7ee752607e274118d549898e5cb23ee954964696937c7b44c5
font_02_sfnt_off00066258.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x66258 46140 bytes
SHA-256: 634cc1d35c4fab061064fb29367a39f2af073f6f48b6633217bb1660d52d7102
javascript_obj0613_001.js pdf-javascript-stream PDF /JS object 613 at offset 0x1E6EC 33 bytes
SHA-256: f35d13ad7cfb9d08f9063691ac68f9bb6db7c4b1fc10982e26c1015f500881e6
Preview script
First 1,000 lines of the extracted script
b ɹ�Nߜ�X����H���d )9Z��, �I�� K
javascript_obj0615_003.js pdf-javascript-stream PDF /JS object 615 at offset 0x1E78D 33 bytes
SHA-256: 77c615245c0c1e3fbd9bcb51b51adbfd380cdd87d798764dd0a2f4875a05452d
Preview script
First 1,000 lines of the extracted script
�C � gJ�h���Wߪ�-"W�5�c�@X�s%�B��
javascript_obj0617_005.js pdf-javascript-stream PDF /JS object 617 at offset 0x1E82D 33 bytes
SHA-256: 9ebd83527fc5baa85a3d7ba0eb865a0ff6bc6890ab7b1fd50390b027a32d3aa7
Preview script
First 1,000 lines of the extracted script
[� � ��ܓ2
+P� �`�A� �0�t3 UN�k�
javascript_obj0619_007.js pdf-javascript-stream PDF /JS object 619 at offset 0x1E8CE 33 bytes
SHA-256: 07d229bd66cc7888bf99e9875e1c62f3f45d488f58f0a4945994ca596020c6a9
Preview script
First 1,000 lines of the extracted script
(� ���) � �d t�� ���X�0���̲: ~
javascript_obj0007_009.js pdf-javascript-stream PDF /JS object 7 at offset 0x20079 33 bytes
SHA-256: 963cf2964f1b593e78c45184ea4fff28f0d869e066148b825abc925d50d1b884
Preview script
First 1,000 lines of the extracted script
���� ���qF� =����g �#&J�2��`��i�#
javascript_obj0156_084.js pdf-javascript-stream PDF /JS object 156 at offset 0x2C7D2 33 bytes
SHA-256: 9c68cb2e365e73e31ba51853b6810675bd0bd8e287d754485999e75eedf3dd7e
Preview script
First 1,000 lines of the extracted script
� �� V��v{tn/h�T����-�^��*K��u���