MALICIOUS
132
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
The sample is a PDF file that contains embedded JavaScript and is related to CVE-2023-26369. The embedded JavaScript likely attempts to download and execute a second-stage payload from URLs such as http://lwi.org.lr/js/. The use of a URL shortener (http://bit.ly/1RyMVp3) suggests an attempt to obscure the final destination.
Machine Learning
- Nyx PDF Classifier clean score 0.0043
Heuristics 6
-
TrueType bitmap font + active content — CVE-2023-26369 related high PDF_CVE_2023_26369_RELATEDPDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
-
Clickable URI uses URL shortener medium PDF_URL_SHORTENER_URIPDF contains a clickable HTTP(S) action whose destination is a URL shortener. This hides the final landing page from static review and is common in phishing redirect PDFs.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://lwi.org.lr/js/
- https://tractiontx.com/ghya
- https://ramez.me/Purchseorder
- https://www.radpdf.com
- https://www.radpdf.com)/Author(Mr
- https://www.pdfescape.com)/CreationDate(D:20160308214439+01
- http://www.dynaforms.com
- http://bit.ly/1RyMVp3
- http://bit.ly/1USrEtA
- https://www.pdfescape.com
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/pdf/1.3/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYou
- http://www.microsoft.com/typography/fonts/default.aspx
- http://crl.microsoft.com/pki/crl/products/CSPCA.crl0H
- http://www.microsoft.com/pki/certs/CSPCA.crt0
- http://crl.microsoft.com/pki/crl/products/tspca.crl0H
- http://www.microsoft.com/pki/certs/tspca.crt0
- http://www.microsoft.com/typography
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000013c9.bina6eacb5f4c318f191f5c7ef56b8a9d24965db43dd12e86dc8eafc984e1163d47 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13C9 | 169476 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.