MALICIOUS
86
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The PDF contains embedded JavaScript, flagged by heuristics as malicious. This script is likely responsible for downloading and executing a second-stage payload, as indicated by the ML classifier's high confidence score and the presence of PRC/3D content which can be used for exploit delivery. The primary attack vector is likely spearphishing attachment.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PRC/3D content in PDF high PDF_PRC_3DPDF contains PRC 3D content. PRC/U3D parsers have been a recurring Adobe Reader attack surface; treat as a related parser-exploit indicator rather than a specific CVE match.
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0044_000.js8f4544955c83181c1e97fa3eb09a7da6b20050c42e656902bdd53da1a74e7116 |
pdf-javascript-stream | PDF /JS object 44 at offset 0x14C | 28231 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.