MALICIOUS
302
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9401
Heuristics 12
-
OpenAction trigger high PDF_OPENACTIONPDF has an /OpenAction that launches, submits, or opens an external target
-
Launch action high PDF_LAUNCHPDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
-
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
-
/Launch action target: cmd\056exe high PDF_LAUNCH_COMMANDPDF /Launch action specifies an executable target.
-
Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
-
JavaScript action low 2 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
PDF JavaScript opens or fetches a remote URL/document low PDF_JS_REMOTE_DOC_FETCHEmbedded JavaScript calls app.openDoc() against a remote filesystem (cFS:'CHTTP'/'CFTP') or app.launchURL() to open an external / base64-encoded URL. This is the JS-driven remote-document / phishing-redirect technique — distinct from a /Launch file dropper. It exploits no CVE; the risk is where the URL leads.Matched line in script
try{app.launchURL("http://localhost:3000/files/pdf.pdf-1777384340.exe",true);}catch(e){} -
External URI low PDF_URIPDF contains an external URL action
-
PDF static-analysis soft budget exhausted low SCAN_INCOMPLETEThe bounded PDF scanner skipped late sub-format walkers after the configured per-file soft deadline. Earlier findings remain valid.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.redteamsecure.com Referenced by PDF JavaScript
- http://www.redteamsecure.com/labs/all_projectsReferenced by PDF JavaScript
- http://dradisframework.org/Referenced by PDF JavaScript
- http://keepnote.org/Referenced by PDF JavaScript
- http://www.exploit-db/google-dorks/Referenced by PDF JavaScript
- http://www.googleguide.com/advanced_operators_reference.htmlReferenced by PDF JavaScript
- http://www.shodanhq.com/help/filtersReferenced by PDF JavaScript
- http://www.shodanhq.com/helpReferenced by PDF JavaScript
- http://www.unshredder.com/Referenced by PDF JavaScript
- https://github.com/trustedsec/socialengineerReferenced by PDF JavaScript
- http://www.paterva.com/web6/products/download2.phpReferenced by PDF JavaScript
- http://www.proofpronto.com/gps-tracking-Referenced by PDF JavaScript
- https://www.spoofcard.com/appsReferenced by PDF JavaScript
- http://toool.us/Referenced by PDF JavaScript
- http://acehackware.com/collections/Referenced by PDF JavaScript
- https://searchwwwReferenced by PDF JavaScript
- http://mblsportalReferenced by PDF JavaScript
- http://dialabc.com/sound/detect/Referenced by PDF JavaScript
- http://www.redteamsecure.com/Referenced by PDF JavaScript
- http://www.brickhousesecurity.com/Referenced by PDF JavaScript
- http://localhost:3000/files/pdf.pdf-1777384340.exeReferenced by PDF JavaScript
- http://facebook.com/redteamsecure/Referenced by PDF JavaScript
- http://twitter.com/redteamsecure/Referenced by PDF JavaScript
- http://www.linkedin.com/in/jtalamantes/Referenced by PDF JavaScript
- http://www.facebook.com/redteamsecureReferenced by PDF JavaScript
- http://twitter.com/redteamsecureReferenced by PDF JavaScript
- http://books.google.com/books/Referenced by PDF JavaScript
- http://money.cnn.com/2013/04/08/technology/security/shodan/Referenced by PDF JavaScript
- http://www.whois.net/Referenced by PDF JavaScript
- http://www.intelius.comReferenced by PDF JavaScript
- http://www.ussearch.comReferenced by PDF JavaScript
- http://www.peoplefinders.comReferenced by PDF JavaScript
- http://www.kali.org/downloads/Referenced by PDF JavaScript
- http://www.rapid7.com/products/metasploit/Referenced by PDF JavaScript
- http://www.rapid7.com/products/metasploit/metasploit-pro-registration.jspReferenced by PDF JavaScript
- http://www.newegg.com/Product/Product.aspxReferenced by PDF JavaScript
- https://www.youtubeReferenced by PDF JavaScript
- http://www.readspeaker.com/voice-demo/Referenced by PDF JavaScript
- https://www.youtube.com/watchReferenced by PDF JavaScript
Open this report in the interactive analyzer, or submit your own file for analysis.