MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
T1041 Exfiltration Over C2 Channel
The PDF contains embedded JavaScript that triggers a form submission to the URL http://www.royal-responder.com/rsp-cgi/respondpro/maxuseradmin.cgi. This action is indicative of a phishing attempt or data exfiltration, where user-submitted data is sent to a malicious server. The ML classifier also flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.7871
Heuristics 8
-
PDF JavaScript submits form data to external URL high PDF_JS_SUBMITFORM_URLPDF JavaScript calls submitForm() with an external HTTP(S) URL. This can send form/document context to a remote endpoint or route the user into a credential-phishing flow. It is a behavioral indicator, not a parser exploit signal.
-
SubmitForm action medium PDF_SUBMITFORMPDF has a /SubmitForm action — form data can be silently posted to an attacker-controlled URL
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
External URI info PDF_URIPDF contains an external URL action
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.royal-responder.com/rsp-cgi/respondpro/maxuseradmin.cgi
- http://www.royal-responde
- http://store.yahoo.com/chesscafe
- http://store.yahoo.com/chesscafe/1439.html
- http://store.yahoo.com/chesscafe/ice165.html
- http://store.yahoo.com/chesscafe/cb51.html
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/iX/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://purl.org/dc/elements/1.1/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0094_000.js20e407ccd789cb0132023d6da178ccdb397dafe1d32ece2b28f5676dad30b566 |
pdf-javascript-stream | PDF /JS object 94 at offset 0x2D3FD | 176 bytes |
stream_013_off00010db0.bin2e883c97a37b5c7db6d2c1efc7acfced439d7f172d00b60721c00090cd9fcbcf |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x10DB0 | 4032 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 15 long base64-like blob(s).
|
|||
stream_014_off00011485.bin378f1f6e0cdc9208fd2ea61c41903a20ee37a30da6dc6497de7a0bb1ebb32fc7 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x11485 | 19966 bytes |
stream_016_off0001864f.bin5c5ca5d6c268284a81de3c178f15e786d14bb87c3208042a04348d2db5127172 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1864F | 60192 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.