MALICIOUS
72
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.001 Spearphishing Attachment
T1027 Obfuscated Files or Information
This PDF sample was flagged as malicious by an ML classifier and exhibits high-risk heuristics. It contains an embedded JavaScript stream and is encrypted with an /OpenAction, indicating an attempt to hide malicious content and execute it upon opening. The document body is unreadable, suggesting it serves as a lure, and the presence of JavaScript points to an attempt to download and execute a secondary payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.7362
Heuristics 2
-
Encrypted PDF carries /OpenAction — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JSPDF declares /Encrypt and also references an executable trigger (/OpenAction). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYou In PDF document text
- http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
- http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
- http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
- http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
- http://www.microsoft.com/typographyIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_163_off008ce3f8.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x8CE3F8 | 20232 bytes |
SHA-256: 3db4b42707d912eb467dc3e1fa0bf6886f6a15e37a5658599e0140b38e0df2ba |
|||
stream_166_off008f1b89.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x8F1B89 | 24864 bytes |
SHA-256: 4954c9d5cd8f64d046a89b56e39c3a0e634eab8983629f1848d00471a093ab8b |
|||
font_00_sfnt_off008b0bcb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8B0BCB | 169476 bytes |
SHA-256: a6eacb5f4c318f191f5c7ef56b8a9d24965db43dd12e86dc8eafc984e1163d47 |
|||
font_01_sfnt_off008c452d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8C452D | 177252 bytes |
SHA-256: c36c6921e42f06a577d06872c5da42d1d6cd6e46526e39abd6a88dd4b5aae47c |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.