MALICIOUS
230
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
The PDF file was detected as malicious by ClamAV with the signature Html.Trojan.Shellcode-19. Heuristics indicate the presence of embedded script payloads and the use of String.fromCharCode, suggesting an attempt to obfuscate malicious code. The extracted artifacts include JavaScript files, further supporting the presence of scripting for malicious purposes. The exact intent of the script is unclear due to obfuscation, but it is likely to download and execute a secondary payload.
Machine Learning
- Nyx PDF Classifier clean score 0.0038
Heuristics 6
-
Obfuscated multi-stage PDF JavaScript heap-spray exploit critical PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAYPDF JavaScript hidden behind nested stream filters and/or a custom in-JS decoder (rolling-XOR stager) decodes to a heap-spray / ROP chain. The spray is only visible after unwinding those layers, which is why the raw heap-spray rules miss it. This is an obfuscated multi-stage Adobe Reader JavaScript exploit; the dropped Windows payload (often named Win.Trojan.Agent by signature AV) is the second stage, not the delivery mechanism.
-
ClamAV: Html.Trojan.Shellcode-19 critical CLAMAV_DETECTIONClamAV detected this file as malware: Html.Trojan.Shellcode-19
-
Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
String.fromCharCode low PDF_FROMCHARCODEString.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules. (matched inside decoded stream)Matched line in script
T* (o += String.fromCharCode\(v\); )Tj T* -
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.hackinthebox.org In PDF document text
- http://forum.hackinthebox.orgIn PDF document text
- http://conference.hackinthebox.orgIn PDF document text
- http://gynvael.coldwind.pl/In PDF document text
- http://www.nynaeve.net/?p=201In PDF document text
- http://www.nynaeve.net/?p=200In PDF document text
- http://j00ru.vexillium.org/?p=194&lang=enIn PDF document text
- http://msdn.microsoftIn PDF document text
- http://www.dumpanalysis.org/blog/index.php/2007/05/15/inter-In PDF document text
- http://www.securityforest.com/wiki/index.php/Exploit:_Stack_Over-In PDF document text
- http://ragestorm.net/distorm/In PDF document text
- http://www.array51.com/static/downloads/appinit.zipIn PDF document text
- http://supportIn PDF document text
- http://ribadeohacklab.com.ar/people_In PDF document text
- http://ribadeohacklab.comIn PDF document text
- http://sales.ourdomain/ordersIn PDF document text
- http://sales.ourdomain/In PDF document text
- http://example/..%255c..%255c..%255cbIn PDF document text
- http://www.informatica64.com/In PDF document text
- http://elladodelmal.blogspotIn PDF document text
- http://blueinfy.com/tools.htmlIn PDF document text
- http://www.edge-security.com/wfuzz.phpIn PDF document text
- http://www.ribadeohacklab.com.arIn PDF document text
- http://elladodelmal.blog-In PDF document text
- http://www.webappsec.org/projects/threat/classes/ldap_injection.shtmlIn PDF document text
- http://www.ribadeohacklab.com.ar/articles/ldap-injection-hitbIn PDF document text
- http://www.sys-In PDF document text
- http://securityvulns.ru/docs3377.htmlIn PDF document text
- http://www.x10security.org/In PDF document text
- http://www.phrack.com/show.phpIn PDF document text
- http://net-square.com/httprint/httprint_paper.htmlIn PDF document text
- http://www.net-security.org/dl/In PDF document text
- http://www.intranode.com/site/techno/techno_articles.htmIn PDF document text
- http://malwareguru.com/kolisar/In PDF document text
- http://updatez.info/etc/getexe.exe?o=1&In PDF document text
- http://wepawet.iseclab.org/index.phpIn PDF document text
- http://www.javascriptsearch.com/guides/Advanced/In PDF document text
- http://www.cha88.cn/safe/fromCharCode.phpIn PDF document text
- http://dean.edwards.name/packer/In PDF document text
- http://www.saltstorm.net/depo/esc/In PDF document text
- http://scriptasylum.com/tutorials/encdec/javascript_encoder.htmlIn PDF document text
- http://www.dennisbabkin.com/php/In PDF document text
- http://www.openwaves.net/download/wayne/WWW2003_WAVES.pdfIn PDF document text
- http://www.jasob.com/In PDF document text
- http://daven.se/usefulstuff/javascript-obfuscator.htmlIn PDF document text
- http://domapi.com/jscruncherpro/In PDF document text
- http://www.stunnix.com/prod/jo/In PDF document text
- http://www.javascript-source.com/In PDF document text
- http://www.syntropy.se/?ct=products/jcepro&target=overviewIn PDF document text
- http://www.semdesigns.com/Products/Obfuscators/In PDF document text
+60 more URL(s)
Extracted artifacts 20
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_056_off00137285.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x137285 | 160644 bytes |
SHA-256: 568c0437cea868045fd8596e431a84e7a6dc46f4a48e0b0c9a04d645d260dfda |
|||
|
Detection
ClamAV:
Html.Trojan.Shellcode-19
Obfuscation or payload:
unlikely
|
|||
stream_060_off00173d6d.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x173D6D | 152904 bytes |
SHA-256: fad776c28108732daeff653191f5e2be7816cba0b9f2068290f5754f548ab6b5 |
|||
stream_061_off0017e673.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x17E673 | 65360 bytes |
SHA-256: 540c8d1242d6d10dbc67ba1af3f7672010ca1643af308cbf371f94598da69ebd |
|||
stream_063_off001958ef.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1958EF | 66220 bytes |
SHA-256: 2525060318e27bf367c1966a57c3c565e989cc0fd7e3ddc2eb4668794031b985 |
|||
stream_064_off001a1563.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1A1563 | 34185 bytes |
SHA-256: 48b466b6818b6c73077148243fbfc826feee03fdb6b776d77b4d921d6c64f9ac |
|||
stream_074_off001f06f5.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1F06F5 | 320784 bytes |
SHA-256: 7a4ea40dfbc3e5a980bf05d92b40098e994311a7796cc954650a337ed97d455f |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Static shellcode analysis found candidate code region(s). Indicators: heap spray 0x04
|
|||
stream_078_off00210c39.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x210C39 | 154893 bytes |
SHA-256: 549e29e2ec93d51d174304aaf1d4d64f3e6a4ca6e471e25ace7de16d52dc4445 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s).
|
|||
stream_080_off0023ae11.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x23AE11 | 158968 bytes |
SHA-256: 3db45c141a72c9010c68fa20e612c26c44c10c98487792b84abf808fd8a6448d |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 shell/COM execution token(s).
|
|||
stream_088_off0027bb94.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x27BB94 | 33777 bytes |
SHA-256: 6c21b809eccbb3a5bbfbd923c3a5eb47aae198579c33b91f61d3e0922d9346c3 |
|||
font_00_cff_off00002207.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2207 | 3034 bytes |
SHA-256: 42637ccfd58bd3bb548f9c75be2c966211ccf1dec908314fb2bcb6aea87cc380 |
|||
font_01_cff_off00002d9d.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2D9D | 4492 bytes |
SHA-256: e3530c1a8fbed04af952a69ae7e1e0cfb3eea53c4ad6c0d59a0ec1bc691e4160 |
|||
font_02_cff_off00003e15.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x3E15 | 7466 bytes |
SHA-256: 0a2977f673b0a7fd1f7ac0cea93c0083507af6f28169d58bf38b3d8fe3e2cb87 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.44, consistent with packed or encrypted content.
|
|||
font_03_cff_off002bc89a.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2BC89A | 4483 bytes |
SHA-256: c5ae3a46b116f0aa15f1d050e20f886e37ead6f18cadd8011201d913e427fd6d |
|||
font_04_cff_off002bdaf6.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2BDAF6 | 7191 bytes |
SHA-256: c93e3ea77ebf9ccc98abdf62ad068e15c052c543d4295f3baccf11c1a14f20c6 |
|||
font_05_cff_off002bf759.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2BF759 | 4364 bytes |
SHA-256: 1215e09394ca940bbf2be54641c67068539a8f0d545f59cc286a868138ef99c0 |
|||
font_06_cff_off002c0dec.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2C0DEC | 6212 bytes |
SHA-256: 6c9497bef0c1eefd9c5093b0a926e34f6ba6917c8acce624984b8a5c3f1ee9a4 |
|||
font_07_cff_off002c3098.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2C3098 | 2553 bytes |
SHA-256: 65a24032906f165bb30ad75d17ac4d1ded4e73da7694434f7edeed6783072813 |
|||
font_08_cff_off002caaf3.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2CAAF3 | 2864 bytes |
SHA-256: a722ddfa44a4570c0117184c5ff1a364d6dc184866e963946763467f4e53dd5c |
|||
font_09_cff_off002e116c.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2E116C | 2263 bytes |
SHA-256: b53f0258a4f5e6ed44633825bc102cf211e6b407fb13f940de3b8c8a116ab8c9 |
|||
font_10_cff_off002e1e3f.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2E1E3F | 2695 bytes |
SHA-256: 5cae38d2c85ce61f5a53abba3b6fec97f97631785fa49cc0708bdb54d9e0d607 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.