MALICIOUS
160
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious Link
T1566.002 Spearphishing Attachment
The PDF contains embedded JavaScript with eval() calls and String.fromCharCode, indicating obfuscated code execution. A visible LOLBin command execution instruction and a call-to-action button suggest the document is designed to trick the user into downloading and running a malicious payload. The embedded JavaScript and file are likely part of this malicious workflow.
Heuristics 13
-
eval() call high PDF_EVALeval() found — commonly used for obfuscated exploit execution
-
Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMANDDocument contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
-
Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
String.fromCharCode low PDF_FROMCHARCODEString.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules.
-
ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.adobe.com/albumreader)/Next
- http://www.adobe.com/imageviewer)/Next
- http://www.adobe.com/getpsalbumstarteredition)/Next
- http://ns.adobe.com/xap/1.0/
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/iX/1.0/
- http://ns.adobe.com/exif/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/photoshop/1.0/
- http://ns.adobe.com/tiff/1.0/
- http://ns.adobe.com/xap/1.0/rights/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/mm/
- http://www.apple.com/DTDs/PropertyList-1.0.dtd
- http://www.adobe.com/AdobePhotoshopAlbum/template
- http://ns.adobe.com/AdobeSVGViewerExtensions/4.0/
- http://www.w3.org/2000/svg
- http://www.w3.org/1999/xlink
- http://ns.adobe.com/Extensibility/1.0/
- http://ns.adobe.com/AdobeIllustrator/10.0/
- http://ns.adobe.com/Variables/1.0/
- http://ns.adobe.com/Flows/1.0/
- http://ns.adobe.com/pdfx/1.3/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_file_obj0094.bin8a5688ed58fb63d62aabff74209c06afa2bff6c6d108fa35ef5b64f8d578607f |
pdf-embedded-file | PDF EmbeddedFile object 94 at offset 0xEF69F | 67549 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 10 eval/decoder/string-building token(s).
|
|||
javascript_obj0102_001.jsb081b3708dce88eee2fa772e45ca44ad95c31aa5ad0f31d844d94358e53e10d7 |
pdf-javascript-stream | PDF /JS object 102 at offset 0x95D | 3542 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
stream_001_off0000241e.bine277eed0d3ead5ded8565d31acda666252038c7de866ddf9e161126dcc9ec77f |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x241E | 1322100 bytes |
font_00_cff_off00015f1b.bin8cde6991bc9606c619ff9f4f7b725327c7eb0ba239bdad78d693fba794855bd3 |
pdf-font-stream | PDF embedded font (cff) at offset 0x15F1B | 1473 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.