MALICIOUS
142
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.2225
Heuristics 8
-
Obfuscated Pidief-style JavaScript loader (stage not decoded) high PDF_PIDIEF_OBFUSCATED_VERSION_GATED_LOADERPDF JavaScript carries a large opaque encoded stage (a letter-delimited numeric character-code array) that is built to be decoded and eval'd, but no exact Adobe Reader CVE could be attributed because the encoding scheme resisted full static decoding. This is the structural fingerprint of the Pidief / multi-CVE exploit-kit loader family — a version-gated obfuscated JavaScript stage with no benign use. Flagged suspicious on its own; an ML/AV signal or a recovered heap-spray pushes it to malicious.
-
JPXDecode + active content — JPEG2000 CVE-family indicator info PDF_JPX_CVE_2018_4990_RELATEDPDF uses /JPXDecode (JPEG2000) alongside JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader JPEG2000 parser exploit families, including CVE-2018-4990, but does not prove the exact malformed JP2/JPX primitive.
-
Travel-support phone-number stuffing scam critical SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
Unusually high stream count medium PDF_MANY_STREAMSPDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
-
ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://app.e-builder.net In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#In PDF document text
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/illustrator/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/t/pg/In PDF document text
- http://ns.adobe.com/xap/1.0/sType/Dimensions#In PDF document text
- http://ns.adobe.com/xap/1.0/g/In PDF document text
- http://en.wikipedia.org/wiki/MIT_LicenseIn extracted file (font_16_sfnt_off001e8b2f.bin)
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0XIn extracted file (font_16_sfnt_off001e8b2f.bin)
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0In extracted file (font_16_sfnt_off001e8b2f.bin)
- http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0aIn extracted file (font_16_sfnt_off001e8b2f.bin)
- http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0In extracted file (font_16_sfnt_off001e8b2f.bin)
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0TIn extracted file (font_16_sfnt_off001e8b2f.bin)
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0In extracted file (font_16_sfnt_off001e8b2f.bin)
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^In extracted file (font_16_sfnt_off001e8b2f.bin)
- http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��In extracted file (font_16_sfnt_off001e8b2f.bin)
- http://www.microsoft.com/pkiops/docs/primarycps.htm0@In extracted file (font_16_sfnt_off001e8b2f.bin)
- http://www.microsoft.com/TypographyIn extracted file (font_16_sfnt_off001e8b2f.bin)
Extracted artifacts 32
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_005_off00027875.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x27875 | 49284 bytes |
SHA-256: f9ff0fadbf5a5fc0f1d71f99b9802931d02ee689608fe30b1038a1d258356b1d |
|||
stream_028_off000524ce.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x524CE | 160749 bytes |
SHA-256: 022c751254df7b4efd7de9ddf386b23755cbb897dafc3c86569567fffc4be2f8 |
|||
stream_036_off000ed00c.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xED00C | 88051 bytes |
SHA-256: 3032eb0c6d52058407b807660382bb3d11bbc4c7e0f17713a12d8c299ace95e3 |
|||
stream_088_off0019992b.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x19992B | 44716 bytes |
SHA-256: 4d41bfc630213098dd25728915396475721e7e2cb2179eb4d49a4345ea3e5ad7 |
|||
stream_101_off001c40ef.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1C40EF | 44584 bytes |
SHA-256: 7a8426f7243e9b6010e5e5e23af6903e84d8c497763dc77a156b635f51e5f5c1 |
|||
stream_123_off0020be21.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x20BE21 | 8101 bytes |
SHA-256: 94391824c7cf6ef54799bc3bf689ea728577eb8e37e214f7ab3c721ff5673e72 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.
|
|||
stream_126_off0020e6e6.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x20E6E6 | 557168 bytes |
SHA-256: 35f401731df11a4eba3502af632e51d68bc394bcb7d34632a331c1ba3f4a0bf6 |
|||
stream_139_off0027e5d6.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x27E5D6 | 72164 bytes |
SHA-256: 31502d4ea074390fde88da7e1c73c84e73fd0b64aa8263435e61d2669123d12c |
|||
icc_01_off0026da7e.icc |
pdf-icc-profile | PDF ICC profile at offset 0x26DA7E | 1972 bytes |
SHA-256: f340aa256d599ebe105af7ae3dad7f62ba8071977ca38a8b4ab896aff9f64003 |
|||
font_00_sfnt_off00025b99.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x25B99 | 30772 bytes |
SHA-256: 01367679343ce79a6fc4a089907f84a26852f1d57490efb563b12c7b897b9d5c |
|||
font_01_cff_off0002755a.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x2755A | 1062 bytes |
SHA-256: 5370e0f6065c4aaff9c37aa605e1a213e2db785123dc82111d00d480e771830c |
|||
font_03_sfnt_off0002c689.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2C689 | 39436 bytes |
SHA-256: 3427219d33632765745ce2b78ecbb4b152e7462e1e34038f4a6cef59df688f1b |
|||
font_04_sfnt_off0003188a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3188A | 38624 bytes |
SHA-256: 2212b1c4ca9933dfe04923552174eded1adcdea1cbf31a88fc93d9c162a391da |
|||
font_05_sfnt_off000355cd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x355CD | 62836 bytes |
SHA-256: a62bc37649d2492d38a542001c0a5bcb9fb02890d7dc0b3d44afdd1c0d3bc1a5 |
|||
font_08_sfnt_off000423ef.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x423EF | 58968 bytes |
SHA-256: 5e3d87f3d0ae181e9159d6dcb65a7182900d73f1797e75eafbb438a6b9f56cac |
|||
font_09_sfnt_off000e0ff7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE0FF7 | 66274 bytes |
SHA-256: b8daeb40b830647a182c4d9582199d60728dd86862ec8bb0bcf4ff01369ea6d3 |
|||
font_11_sfnt_off0012351f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12351F | 5911 bytes |
SHA-256: e808be391551db358aced667fffcc4990b1bace23c8441813a45db8c43193930 |
|||
font_12_sfnt_off00194e2e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x194E2E | 24680 bytes |
SHA-256: 6e56e6c0a44ee97776eedf3b8e5eca20ba15183b185966e87a2142df54669fda |
|||
font_14_sfnt_off001bf60d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1BF60D | 24680 bytes |
SHA-256: caed6ac633a2da80c968b71fc4d1cdb7c9960b0156f86b79a6f0165ff1926226 |
|||
font_16_sfnt_off001e8b2f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E8B2F | 391808 bytes |
SHA-256: 200f3d8e95a05d1a25fdc29c99c7db4a1222232578809ed0080ad13aca245e02 |
|||
font_17_cff_off00209ffe.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x209FFE | 6131 bytes |
SHA-256: 8914ed0838429a45c078a7a5ff7c375684cef029b480ec3d3d04d1abdf799b7b |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.45, consistent with packed or encrypted content.
|
|||
font_19_cff_off0020e074.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x20E074 | 1817 bytes |
SHA-256: 88028f0b45feee0c2df07b1a79e9c5285add8de8a0484a058758d8e1c2b9622b |
|||
font_20_cff_off00272c4c.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x272C4C | 4146 bytes |
SHA-256: 7446e52faf91e8fd6b50b3491118f38b9b3386e570e04ea1fcee134dc017e1fb |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.
|
|||
font_21_cff_off0027576c.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x27576C | 2266 bytes |
SHA-256: 58c302bbba1c3365e2b4bc85072081e5aaf0e065dcab5c556611bc137c98e1bc |
|||
font_22_sfnt_off00279c78.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x279C78 | 60476 bytes |
SHA-256: 08fd2603b6ca8399c8a63f9caf2b0e8ca6198711253cb14df9c7a978c2fc9132 |
|||
font_24_sfnt_off002847bb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2847BB | 39192 bytes |
SHA-256: 4930e0e6c1277fe8c4b567d3930100726b301e56398e4e8517b873cca6a13dac |
|||
font_25_sfnt_off00287fc1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x287FC1 | 52468 bytes |
SHA-256: 91745bfe83b055da1cc0a6f7d1882c548cac354d21111d4f37eec388a70db95d |
|||
font_26_sfnt_off002a424b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2A424B | 55336 bytes |
SHA-256: f742c66e55645a27454632bf8a7beca5a27a477ddcdc67d72723a51e9d451bf1 |
|||
font_27_sfnt_off002ab37b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2AB37B | 27208 bytes |
SHA-256: 3ed66c6c094ec7667e11e1df731821bdfbd05d17797e64112f0b09327eb8317a |
|||
font_28_cff_off00305a0e.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x305A0E | 332 bytes |
SHA-256: 20d9df407a59df7de5335c8f2f208c143ddd8c19c3c23c1528775e210baf931c |
|||
font_29_sfnt_off003124b9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3124B9 | 23600 bytes |
SHA-256: e621da023c0890d9e073f3b5c84a51c52060f8056d09688a01bfd47c0c242107 |
|||
font_30_sfnt_off003536ce.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3536CE | 36444 bytes |
SHA-256: b9cc1b7d8ab94b279b75b03d0d8b10299e57d0fd58886799ee1c1d7eec11a997 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.