MALICIOUS
118
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.001 Malicious Link
The PDF sample contains heavily obfuscated JavaScript, triggered by the CVE-2009-4324 vulnerability via the media.newPlayer sink. The deobfuscated JavaScript streams indicate that the primary intent is to download and execute a second-stage payload. The obfuscation techniques and the use of a known exploit point to a malicious document designed for initial payload delivery.
Heuristics 5
-
media.newPlayer — CVE-2009-4324 critical CVE exact CVE_2009_4324PDF JavaScript calls media.newPlayer — CVE-2009-4324 is a use-after-free in Adobe Reader's multimedia plugin triggered by media.newPlayer(). Actively exploited as a zero-day in December 2009. (identified after JavaScript deobfuscation)
-
eval() call high PDF_EVALeval() found — commonly used for obfuscated exploit execution
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj111711_000.jsb5a8ee8f707ed5f24e6462f5276f8482d61a5a0e1bd797a0240c2090fccce0cd |
pdf-javascript-stream | PDF /JS object 111711 at offset 0x18E | 2814 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 5 long base64-like blob(s).
|
|||
javascript_obj111712_001.js0eca76d6e3a6adaea83db699e9b09e25f2c78dab59b7c422e0222d5b89a75512 |
pdf-javascript-stream | PDF /JS object 111712 at offset 0xCC2 | 10838 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 6 long base64-like blob(s).
|
|||
javascript_obj111713_002.js0392b72b27b7d75dbe81d8aa15016485f053e4baaf03d6ce8f826cddf9ecd9f5 |
pdf-javascript-stream | PDF /JS object 111713 at offset 0x374E | 2502 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s). Carved artifact contains 4 long base64-like blob(s).
|
|||
legacy_pdfkit_stage_000.js14d9d23d619682a659b666d1537fbe47a8cc4db49b0c37d63714847d39b24a42 |
deobfuscated-js | multi-marker percent-array decoded JavaScript at offset 0xCC2 | 1080 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
legacy_pdfkit_stage_001.jsfa44c3a6a5df9dd0c4918db03b8a33dc1e24bba8204a13d66510a81c2b2e6f17 |
deobfuscated-js | multi-marker percent-array decoded JavaScript at offset 0x374E | 166 bytes |
legacy_pdfkit_stage_002.js1c96ee696ace6892c53355b89b1ea96f52cca8e3a6b5b4fe55099399bf524996 |
deobfuscated-js | multi-marker percent-array combined decoded JavaScript at offset 0xCC2 | 1247 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s).
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.