SUSPICIOUS
42
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
The PDF contains embedded JavaScript, indicated by the 'PDF_EMBEDDED_SCRIPT_PAYLOAD' heuristic and the presence of a '.js' file among extracted artifacts. This script is likely designed to download and execute a secondary payload from a suspicious URL found in the extracted data. The document body is heavily obfuscated and unreadable, providing no direct clues to its intent beyond the technical indicators.
Machine Learning
- Nyx PDF Classifier clean score 0.0001
Heuristics 3
-
Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.kjwd.ru/js.js In PDF document text
- http://wepawet.csIn PDF document text
- http://www.honeynet.org/papers/mwsIn PDF document text
- https://projects.honeynet.org/capture-hpcIn PDF document text
- http://wepawet.cs.ucsb.edu)]TJ/F56In PDF document text
- http://wepawet.cs.ucsb.eduIn PDF document text
- http://cve.mitre.org/In PDF document text
- http://www.mozilla.org/rhino/In PDF document text
- http://code.google.com/p/spybyeIn PDF document text
- http://isc.sans.org/diary.html?storyid=6739In PDF document text
- http://www.clamav.net/In PDF document text
- http://carnal0wnage.blogspot.com/2009/04/In PDF document text
- http://www.secureworks.com/research/tools/In PDF document text
- http://www.edup.tudelft.nl/In PDF document text
- http://htmlunit.sourceforge.net/In PDF document text
- http://www.spamcop.net/In PDF document text
- http://www.theregister.co.uk/2008/04/25/mass_In PDF document text
- http://www.theregister.co.uk/2008/09/16/In PDF document text
- http://www.theregister.co.uk/2010/01/15/ie_In PDF document text
- http://code.google.com/apis/safebrowsing/In PDF document text
- http://pfaedit.sf.net/In PDF document text
Extracted artifacts 11
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_001_off000013fd.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x13FD | 17889 bytes |
SHA-256: 8b25f11cb863a1c282e401eff0bbdb8581d9f3615e01dc22cdcd7176f582c145 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 shell/COM execution token(s).
|
|||
stream_019_off00025baf.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x25BAF | 17222 bytes |
SHA-256: f948491e0a7cbc0daaae387d1e83e9b36a54c0346d16b133f0536ad6d8c7a721 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
|
|||
stream_023_off0003189b.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3189B | 21001 bytes |
SHA-256: efdf1fae43b5201061838f74dddd0cad8b9ebfa6cf02fe6779baae5876c337f8 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
|
|||
icc_00_off0000e4a1.icc |
pdf-icc-profile | PDF ICC profile at offset 0xE4A1 | 1296 bytes |
SHA-256: 94722fe267764797f8887379cc0d355f5118beb3d186e087bfbd9e1a3f2d3f49 |
|||
icc_01_off0000e7c8.icc |
pdf-icc-profile | PDF ICC profile at offset 0xE7C8 | 1456 bytes |
SHA-256: 2a18161bb96fd584d19e737ce294732789e0e8e6ae8c8e4e5f09f1b138232a63 |
|||
font_00_sfnt_off0000ed4f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED4F | 15780 bytes |
SHA-256: 99d0de9664d085c75a951ff59e91eacf8a132a975cf483aa975f77ee67342b28 |
|||
font_01_sfnt_off00020752.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x20752 | 14344 bytes |
SHA-256: 410716127de6c4963757aa5c4c4f4a5b4d2cb4b9581f068439028de2d60c2451 |
|||
font_03_type1_off00029e5e.bin |
pdf-font-stream | PDF embedded font (type1) at offset 0x29E5E | 7985 bytes |
SHA-256: 873445e2063a5fa4446eacfeb2c63fc4a36d92086f0ae8d63a3312251b755bb2 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.80, consistent with packed or encrypted content.
|
|||
font_04_type1_off0002bc0d.bin |
pdf-font-stream | PDF embedded font (type1) at offset 0x2BC0D | 7085 bytes |
SHA-256: c9145a0c4b2df139823105a635b20d43cb41234e9af5b0dd9b16793d7a1d9ee2 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.86, consistent with packed or encrypted content.
|
|||
font_05_type1_off0002d7de.bin |
pdf-font-stream | PDF embedded font (type1) at offset 0x2D7DE | 16823 bytes |
SHA-256: 915312615d1303a832fab3148f9a7fff47d75d8c24ac1e16c9ebb2a50a0ea9f5 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
|
|||
font_07_type1_off00036a4a.bin |
pdf-font-stream | PDF embedded font (type1) at offset 0x36A4A | 17183 bytes |
SHA-256: 866feb7f4a33302f6375c86fe1af85f9bbceee09ae1574f41f679ff5f8a38ba6 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.