Obfuscated multi-stage PDF JavaScript heap-spray exploit

PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAY

← All detection heuristics · PDF

critical CVE related PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAY

What it means

PDF JS behind nested filters / a custom rolling-XOR decoder de-obfuscates to a heap-spray / ROP chain.

Why it fires

The PDF JavaScript is hidden behind nested stream filter chains (e.g. ASCIIHexDecode/FlateDecode/ASCIIHexDecode) and/or a custom in-JS decoder (a rolling-XOR 'ffts' stager that XORs each byte with a feedback key and evals the result). After the analyzer unwinds those layers, the recovered stage contains a heap-spray / ROP chain (repeated 0c0c/9090/4141 landing words plus shellcode). A spray that only appears after de-obfuscation is never benign — this is an obfuscated multi-stage Adobe Reader JavaScript exploit. ClamAV often labels these by the dropped Windows payload (Win.Trojan.Agent), which is the second stage, not the delivery; the family is attributed at related confidence because the exact Reader CVE trigger may sit in an even deeper layer.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH