MALICIOUS
366
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The sample is a malicious PDF that leverages embedded JavaScript, indicated by PDF_JAVASCRIPT and PDF_EMBEDDED_SCRIPT_PAYLOAD heuristics. The JavaScript contains eval() calls and uses String.fromCharCode, suggesting obfuscation and exploit activity. The ClamAV detection of Win.Worm.Mantan-1 further confirms its malicious nature. The embedded script likely acts as a downloader for a secondary payload.
Machine Learning
- Nyx PDF Classifier suspicious score 0.4690
Heuristics 11
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
-
ClamAV: Win.Worm.Mantan-1 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Worm.Mantan-1
-
ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAVClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
-
eval() call high PDF_EVALeval() found — commonly used for obfuscated exploit execution
-
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
String.fromCharCode low PDF_FROMCHARCODEString.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules.
-
ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://linkshare.clarence.com/add.php?own=16
- http://www.clarence.com/linkshare/images/linkshare.gif
- http://ads.dada.it/adclick/CID=000028d96c11eee700000000/SITE=CLARENCE/AREA=CULTURA/AAMSZ=1X1/ACC_RANDOM=1070113316590/PAGEID=995000
- http://linkshare.clarence.com/go.php?adm=0&id=243&ids=16
- http://ads.dada.it/adclick/CID=00001ed4912d708d00000000/SITE=CLARENCE/AREA=CALENDARIO/AAMSZ=150X150/ACC_RANDOM=1069087938670/PAGEID=213033
- http://ads.dada.it/adclick/CID=00002a69912d708d00000000/SITE=CLARENCE/AREA=CALENDARIO/AAMSZ=120X240/ACC_RANDOM=1069087938950/PAGEID=213033
- http://ads.dada.it/adclick/CID=000028d86c11eee700000000/SITE=CLARENCE/AREA=CULTURA/AAMSZ=1X1/ACC_RANDOM=1069087939280/PAGEID=213033
- http://www.icra.org/ratingsv02.html
- http://www.clarence.com/calendario2004/
- http://www.rsac.org/ratingsv01.html
- http://www.clarence.com/
- http://www.clarence.com/freeinternet/
- http://chat.clarence.com/
- http://forum.clarence.com
- http://www.clarence.com/oroscopo/
- http://www.clarence.com/cartoline/index.php
- http://www.clarence.com/calendario2004/index.php
- http://www.clarence.com/city/tobestrip/
- http://sms.clarence.com
- http://search.clarence.com
- http://www.clarence.com/qpid/
- http://webmail.clarence.com/
- http://giochi.clarence.com/
- http://search.clarence.com/links/
- http://www.clarence.com/meteo/
- http://blog.clarence.com/
- http://www.clarence.com/cgi-bin/redir.cgi?http://big.clarence.com/
- http://ads.dada.it/jserver/SITE=
- http://ads.dada.it/adclick/SITE=
- http://ads.dada.it/nserver/SITE=
- http://www.dada.net
- http://bacionimegan.clarence.com
- http://forum.clarence.com/forumdisplay.php?s=&forumid=160
- http://www.clarence.com/images/symbols/arrow.gif
- http://www.clarence.com/misc/incontri-supereva/
- http://www.clarence.com/city/tobestrip/images/stripcard_invio.gif
- http://webmail.clarence.com
- http://www.clarence.com/images/smallicons/novita/icocards.gif
- http://blog.clarence.com
- http://www.clarence.com/images/smallicons/novita/icoblog.gif
- http://www.clarence.com/images/tmp/ico03.gif
- http://www.clarence.com/contents/cultura-spettacolo/speciali/calendari2003/
- http://www.clarence.com/contents/societa/memoria/
- http://www.clarence.com/contents/societa/cowjones/
- http://www.clarence.com/contents/partire/webcam/
- http://www.clarence.com/contents/societa/wwwar/
- http://www.clarence.com/contents/cultura-spettacolo/cinema/recensioni/
- http://linkshare.clarence.com
- http://www.clarence.com/linkshare/scripthp.php?id=16
- http://www.clarence.com/calendario2004/pics/img3f4865a43cb8c.jpg
+60 more URL(s)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_pdf_script_0002649b.bin1afbf06715f69b90b6215e0696d6a5a5f7bc0f388ed08f731077aa73d90fb52e |
pdf-embedded-script | PDF decompressed stream script payload at offset 0x2649B | 2047852 bytes |
|
Detection
ClamAV:
Win.Worm.Mantan-1
Obfuscation or payload:
likely
Carved artifact contains 20 shell/COM execution token(s). Carved artifact contains 6 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
font_00_sfnt_off00010493.bin4958e4127f8f663249329b037bcce131dc34b24048f789075c4cc54e9efa4551 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10493 | 15388 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.