MALICIOUS
214
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
This PDF document contains JavaScript that utilizes eval() and String.fromCharCode() to obfuscate its actions, a common technique for exploiting PDF vulnerabilities. The script constructs a URL, likely for downloading a second-stage payload, and the document's content suggests an advance-fee scam. The embedded JavaScript is designed to exploit PDF reader vulnerabilities, leading to the execution of malicious code.
Machine Learning
- Nyx PDF Classifier malicious score 0.9284
Heuristics 10
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
-
eval() call high PDF_EVALeval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
Additional-actions dictionary low PDF_AAPDF defines /AA (Additional Actions) that references an executable action (JS/JavaScript/Launch/SubmitForm) — can auto-trigger on document or widget events. Form-field calc/format/validate/keystroke handlers in legitimate interactive forms commonly fire this, so it is reported as a low-weight signal; weaponised auto-execution is flagged by stronger rules (PDF_OPENACTION, encrypted-with-JS, etc.)
-
String.fromCharCode low PDF_FROMCHARCODEString.fromCharCode found — used to construct payload strings dynamically. Common in benign JavaScript libraries for codepoint manipulation, so this alone is informational; weaponised use is also caught by the dedicated fromCharCode-stage and exploit-shape rules. (matched inside decoded stream)
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.color.org
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/iX/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://purl.org/dc/elements/1.1/
Extracted artifacts 22
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
PM.joboptions5cf97cfee76c3bcd5d889b3138e05d6571e7d097b173dd3eee4be6813c9dd743 |
pdf-embedded-file | PDF EmbeddedFile object 286 at offset 0x11F26C | 12758 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 12 long base64-like blob(s).
|
|||
javascript_obj0076_003.jsa5f5009227761230d839f919a5aa1e9f40b9c1b147491e759937ef82d3cd3869 |
pdf-javascript-stream | PDF /JS object 76 at offset 0x7040 | 5775 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
stream_132_off0012f001.binea7c22bf258013d88dc4fbac5db0c19406c9156e694a3c273eb86c8ec652c23c |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x12F001 | 5491 bytes |
font_00_cff_off00123662.binf48d5dbacea57fca93af784acb2a0e2cf9e7671a3148cc6d71105d38f51dffa9 |
pdf-font-stream | PDF embedded font (cff) at offset 0x123662 | 7516 bytes |
font_01_cff_off00124eda.bin5fe5444d220c0637fe39595be88dc6481406134a7163fd35a46204e50f4e9c44 |
pdf-font-stream | PDF embedded font (cff) at offset 0x124EDA | 10215 bytes |
font_02_cff_off00126eb6.bin4abd877f974796feeddb3585e3d135e071ac4bafa6b070cb02efd181aa364e6d |
pdf-font-stream | PDF embedded font (cff) at offset 0x126EB6 | 4771 bytes |
font_03_cff_off00127e34.bin2e36624526c529ff90819ca5f054b8e0f89abb6145e12023180a87d7ac7b61f1 |
pdf-font-stream | PDF embedded font (cff) at offset 0x127E34 | 5292 bytes |
font_04_cff_off00129004.binea5d46d1d4b43ba8bf5a5b210b7b88e58b83cf3eb801317f79e4493423d8a5ff |
pdf-font-stream | PDF embedded font (cff) at offset 0x129004 | 8141 bytes |
font_05_cff_off0012a912.bin786e7cdc1d0fd354bb2a994d3b45be7b64e91842ee20bc7f9a6157e713d0b476 |
pdf-font-stream | PDF embedded font (cff) at offset 0x12A912 | 146 bytes |
font_06_cff_off0012a9f7.bindc566301c63842a5757792ba9336925fcfe276ea565fbd5b9600b3332126e5dc |
pdf-font-stream | PDF embedded font (cff) at offset 0x12A9F7 | 5157 bytes |
font_07_cff_off0012bada.bina3501e130759b3ba73909eae6e0af97031e5d373d4a8a93c1b82dea3d9851425 |
pdf-font-stream | PDF embedded font (cff) at offset 0x12BADA | 1739 bytes |
font_08_cff_off0012c23f.bin3c057c6244a8fcf0961b80e0b7a80d502b648f702ee27382548077c6e7df4e3f |
pdf-font-stream | PDF embedded font (cff) at offset 0x12C23F | 11304 bytes |
font_09_cff_off0012e6bd.bina8af6347a230dac0006ca0233f494a295b0e97e3ed793bcacb8ba23cb38b4574 |
pdf-font-stream | PDF embedded font (cff) at offset 0x12E6BD | 2705 bytes |
font_11_cff_off00130132.bin57c71b2d06985da171e19ab6488216e0de7fa2e17ba548fc5dd61f7b3ea63404 |
pdf-font-stream | PDF embedded font (cff) at offset 0x130132 | 3851 bytes |
font_12_cff_off00130ea8.binaeabdd7296e7458619dfe824fce60e81716501eda4fa455cd630690ce30bed2a |
pdf-font-stream | PDF embedded font (cff) at offset 0x130EA8 | 3345 bytes |
font_13_cff_off00131985.bin1d51878934c5bd2b07816a6c8077b40f373f2bbe97d6f802f45e663d8ab0e2d8 |
pdf-font-stream | PDF embedded font (cff) at offset 0x131985 | 5150 bytes |
font_14_cff_off00132a23.bina04986f1fdde2996f1228f8c692d54f0ca73cb78a3d779f31e15b95b375a6001 |
pdf-font-stream | PDF embedded font (cff) at offset 0x132A23 | 4950 bytes |
font_15_cff_off0013c91a.bin89a6b2d97af1a2b7960aacec660e183f971d3d859beac54f6ae55819e2672410 |
pdf-font-stream | PDF embedded font (cff) at offset 0x13C91A | 4067 bytes |
font_16_cff_off0013d235.bin1d6653dda9b5ecb635d47f50767b97ba9ebca047a4b68e16e7a24147919fb589 |
pdf-font-stream | PDF embedded font (cff) at offset 0x13D235 | 19906 bytes |
font_17_cff_off00140d73.bin434f718c585b22a67dcc915c24f828927af18ffedc22ea7d0eb93e101fc602d8 |
pdf-font-stream | PDF embedded font (cff) at offset 0x140D73 | 11541 bytes |
font_18_cff_off00142fd3.bin7b5e181ac903033fc628337c44ddd6e6d1de02eb9762c5a93f0665ac25515bc1 |
pdf-font-stream | PDF embedded font (cff) at offset 0x142FD3 | 8651 bytes |
font_19_cff_off001464f3.binfcb33e06b4ac9ba87b955794e41142d4ec359c3109633f97f4952d320c7a5071 |
pdf-font-stream | PDF embedded font (cff) at offset 0x1464F3 | 2131 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.