MALICIOUS
116
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1055.001 Process Injection
T1027 Obfuscated Files or Information
The PDF is encrypted and contains an /OpenAction, indicating that its payload is hidden from static analysis and likely executed upon opening. High stream counts and the presence of JBIG2 encoded streams suggest obfuscation techniques are being used to conceal malicious content. The ML classifier also flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.6103
Heuristics 6
-
Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JSPDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
-
JBIG2Decode filter medium PDF_JBIG2JBIG2 image decoder present — historically used in zero-click exploits
-
Unusually high stream count medium PDF_MANY_STREAMSPDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
-
PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LUREPDF has 2 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://purl.org/dc/elements/1.1/
Extracted artifacts 32
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
jbig2_00_off000021ab.bincbffd3964423edf09c7f242aebef6d3f63aedb73d3d71ee8e22a918689574340 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x21AB | 39570 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
|
|||
jbig2_01_off0001ee9b.binb67070970f4bdfadba817ea9073cd6b172e0de62e21a70b666d88897fa27f9a5 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x1EE9B | 101 bytes |
jbig2_02_off0001f116.binf4cf5148fbbbd76da901c97ee1cbffd28f3bdbe43c5ce555d3d67a8f39065095 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x1F116 | 3219 bytes |
jbig2_03_off0001ff17.binbbdc51f493e4af3cba62b9611297c044dea34691c4b4698721d48829ece91c34 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x1FF17 | 101 bytes |
jbig2_04_off0002046f.bina495c926258045fb211a98367e7e9baa9650b0f7255c0e39d067d540323d4913 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x2046F | 7432 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
|
|||
jbig2_05_off00022a0e.bin0ac0f279d9619987eccde9115a15e9950c0e97dd246311823fd8b487e18f0f6f |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x22A0E | 7673 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
|
|||
jbig2_06_off000256ad.binff5f2f29a55ae77bf0414ab006979f7254b5472035fd93f9c4bbbf5fd879c2d4 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x256AD | 13139 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
|
|||
jbig2_07_off00033b8c.bin3d65e766866dd0163d0aefadd979b60297f86ff5f06f8dbf75e1bc9ef14e1de1 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x33B8C | 14831 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
|
|||
jbig2_08_off0003ed80.bin91b12eeabea68fadd79f40d424875992a7369b2b134c755b6c44e49da1a3b3f8 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x3ED80 | 14266 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
|
|||
jbig2_09_off00042c15.bin17b2101290d6c0068238fbe96574fbf9c3ac044a1264d2d97e2bb41da37cd35c |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x42C15 | 5413 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.94, consistent with packed or encrypted content.
|
|||
jbig2_10_off0004481c.binf4d938a568ce6726e1a18099f069fcc60b36176052bcc2e94e5e7f5470860f7b |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x4481C | 8311 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
|
|||
jbig2_11_off000471fe.bin925b10cd1b7d8b69847fcd342099e43adfcd149289b6fa49b8fd7da8d36d458c |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x471FE | 10218 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_12_off0004a32f.bin5e059596dbca7c0b175076444cabba4e103e911752c72e378570371fe4ca2ea4 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x4A32F | 9695 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_13_off0004d222.bin9512e27b25489bdeefe93afe7c769d099107521869c08e3738feb234ad609f89 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x4D222 | 10600 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_14_off00050480.bin804f8b996a1bd024dabb76e8e7c2603a444bbc7918af26fd443d6033cc201f76 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x50480 | 10056 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_15_off00053499.bin55759471ec9cd77079c1c10fa6222639ad2ebd271c1016dc7dbe4356ada7db36 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x53499 | 9934 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_16_off000565a8.bind3662652aa9851e27cb3445c368ce7ba57cf052cbec1be742c7ee7bc24a990fd |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x565A8 | 9989 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_17_off000590d8.bin9ee270917990d880915e9e44bd90601904b1dcc8e1ef981ae1d9cac1aefdaec2 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x590D8 | 4735 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.93, consistent with packed or encrypted content.
|
|||
jbig2_18_off0005ad23.bin883247e8e8db0bb03c6f020a061f0f30c010dfcf5d0ed84fe82c6cf5a19d57ce |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x5AD23 | 8821 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_19_off0005d350.bin01086ba4fd062979185ef459799a3d95387d2a550e976d4d46b309d30e6e4105 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x5D350 | 3558 bytes |
jbig2_20_off0005eb9a.bin961662a92703daf6f297bd9f5ea5f1cdeb72a13dd1ca0f8711ec88926b026c60 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x5EB9A | 9594 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.97, consistent with packed or encrypted content.
|
|||
jbig2_21_off00061dad.bine0fcf52df3d0e19fead4b8cb6c23d85446c3035429db18386309e16efbf4e9c1 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x61DAD | 11497 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
|
|||
jbig2_22_off00065310.bin12937083c89cb8eef3e93dda7d544fcdd523c37658f890619329d952e40ad00d |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x65310 | 6999 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.95, consistent with packed or encrypted content.
|
|||
jbig2_23_off00066fdb.binecc801f97caf72007787081a1d2af8e0bb977e7caa382ceb2b7273ee2c966616 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x66FDB | 193 bytes |
jbig2_24_off00067fdb.bin7647a0517a465c35a8e55da4d65b95ba447fd605d6cac00461ec77a39085a718 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x67FDB | 15040 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
|
|||
jbig2_25_off0006bf55.binf19c0a33633582a1cf6748061bfe592bb3bdcbc0fb359661a519badebd36a15d |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x6BF55 | 4610 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.93, consistent with packed or encrypted content.
|
|||
jbig2_26_off0006d7c2.bin1e25f52629260e3ca08242003d9523e123ccd4990fb0d2edcd0900fc868b03f5 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x6D7C2 | 7050 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.96, consistent with packed or encrypted content.
|
|||
jbig2_27_off0006f4c0.bind3e7bb9b1a9af9ed525c9e4fe5c4bfeb553cf509da88d69e930bc0ea409764ad |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x6F4C0 | 192 bytes |
jbig2_28_off000703fc.binef14fef307575c89aef0d7095772ff0ac9864c371bcd457f370963c98cde0d66 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x703FC | 14164 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
|
|||
jbig2_29_off00074ae6.binfd575ab19a9eb2bcc3ffd16df38f79369f3346f1d601db3f3d9ca4821af270f0 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x74AE6 | 14860 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.98, consistent with packed or encrypted content.
|
|||
jbig2_30_off000796e0.bin77f410aa86424ad5f3670249f743ad0d6a08b30b3aaba2ee3b5f9772e0daf6b3 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x796E0 | 16604 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.
|
|||
jbig2_31_off0007d92f.binb23ea51823cce72e52644c330330d1d34e58605df2997834bbad878b9e5b49e8 |
pdf-jbig2-stream | PDF JBIG2 stream at offset 0x7D92F | 197 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.