MALICIOUS
90
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious File
The PDF contains embedded JavaScript, indicated by PDF_JAVASCRIPT and PDF_JS heuristics. The presence of an eval() call (PDF_EVAL) suggests obfuscated code execution. The ML classifier strongly flags this PDF as malicious. While no specific URLs or commands were extracted, the pattern of embedded JavaScript in a PDF commonly leads to the download and execution of further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9607
Heuristics 6
-
eval() call high PDF_EVALeval() found — commonly used for obfuscated exploit execution (matched inside decoded stream)
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/tiff/1.0/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/exif/1.0/
- http://ns.adobe.com/photoshop/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 7
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0001_000.jsf963bc9aa8b28a160db694a5e4281d29b1e0a968bfe6b616a9f9b49580dd9907 |
pdf-javascript-stream | PDF /JS object 1 at offset 0x621B | 533 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s).
|
|||
icc_00_off000110f6.icc2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
pdf-icc-profile | PDF ICC profile at offset 0x110F6 | 3144 bytes |
font_00_cff_off00011b5b.binaa828f1ed1bd0c1309e5cd820e7626c7429316961c7c5f280e740f34c801faca |
pdf-font-stream | PDF embedded font (cff) at offset 0x11B5B | 8143 bytes |
font_01_cff_off000136d7.bin81969d28eeb80b957e1245930ec30696e05a1db8fd79483fb0fbc8ddc908172c |
pdf-font-stream | PDF embedded font (cff) at offset 0x136D7 | 8133 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.41, consistent with packed or encrypted content.
|
|||
font_02_cff_off000151fa.bin99ed3369cd49fa318d2c208ae06e6e76dc664cd66cb0c4fc6aa7b272a5506e3c |
pdf-font-stream | PDF embedded font (cff) at offset 0x151FA | 11009 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.
|
|||
font_03_cff_off00017456.bindbb969be82f2180cb8eb904017632591d9eb1f43e0ea6982165f284373412a2a |
pdf-font-stream | PDF embedded font (cff) at offset 0x17456 | 10398 bytes |
font_04_cff_off0001960b.binff9beecbbbe819260d1e4f7976be000ed3302326e4e7f5cdce28cc833aecea33 |
pdf-font-stream | PDF embedded font (cff) at offset 0x1960B | 6954 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.