MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1559.002 Component Object Model Hijacking
The sample is a PDF file flagged by ClamAV as Win.Exploit.CVE_2018_4990-6599478-0. High-severity heuristics indicate JPXDecode with active content and a malformed JPEG2000 box structure, strongly suggesting exploitation of CVE-2018-4990. The ML classifier also returned a high probability of maliciousness. No scripts were extracted, but the PDF structure itself indicates an exploit attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9940
Heuristics 7
-
JPXDecode + active content — JPEG2000 CVE-family indicator high PDF_JPX_CVE_2018_4990_RELATEDPDF uses /JPXDecode (JPEG2000) alongside JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader JPEG2000 parser exploit families, including CVE-2018-4990, but does not prove the exact malformed JP2/JPX primitive.
-
Malformed JPEG2000/JP2 box structure high PDF_JP2_BOX_ANOMALYPDF embeds JPEG2000/JP2 data with malformed box sizes. This is a parser-exploit indicator for JPX/JPEG2000 CVE families, not a unique CVE fingerprint.
-
ClamAV: Win.Exploit.CVE_2018_4990-6599478-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Win.Exploit.CVE_2018_4990-6599478-0
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LUREPDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_cff_off0000476b.bin3ad89875e6fb7800b92b2a7d51b20b4698616ec3f17bd584488b4745cd64e011 |
pdf-font-stream | PDF embedded font (cff) at offset 0x476B | 1578 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.