MALICIOUS
234
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
T1204.002 Malicious Link
The PDF contains numerous heuristics related to active content and known exploit CVEs (CVE-2018-4990, CVE-2010-0188, CVE-2023-26369), indicating it's designed to exploit vulnerabilities. The document body and heuristics suggest a lure for payment or personal information, consistent with phishing or invoice scams. Embedded JavaScript streams and SubmitForm actions likely facilitate the exfiltration of user-provided data or the execution of further malicious actions.
Heuristics 15
-
JPXDecode + active content — JPEG2000 CVE-family indicator high PDF_JPX_CVE_2018_4990_RELATEDPDF uses /JPXDecode (JPEG2000) alongside JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader JPEG2000 parser exploit families, including CVE-2018-4990, but does not prove the exact malformed JP2/JPX primitive.
-
CCITTFaxDecode + active content — LibTIFF CVE-family indicator high PDF_CCITT_CVE_2010_0188_RELATEDPDF uses /CCITTFaxDecode together with JavaScript, XFA, or RichMedia indicators. This matches the delivery pattern for Adobe Reader LibTIFF/CCITTFax parser exploit families, including CVE-2010-0188, but does not prove the exact malformed TIFF primitive.
-
TrueType bitmap font + active content — CVE-2023-26369 related high PDF_CVE_2023_26369_RELATEDPDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
-
SubmitForm action medium PDF_SUBMITFORMPDF has a /SubmitForm action — form data can be silently posted to an attacker-controlled URL
-
Unusually high stream count medium PDF_MANY_STREAMSPDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
ASCII85Decode filter (with exploit indicators) low PDF_FILTER_85ASCII85 encoding filter present alongside exploit delivery indicators — uncommon outside of obfuscation
-
Optional Content Group with action trigger low PDF_OPTIONAL_CONTENTOptional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.threesquaredproduction.com/bac-fpe-2016.html)/Type/Action/S/URI
- http://www.eventexhibitions.co.uk/)/Type/Action/S/URI
- http://www.faceuptv.com/)/Type/Action/S/URI
- http://www.adexpo.co.uk/)/Type/Action/S/URI
- http://www.igbaffiliatehotels.com/)/Type/Action/S/URI
- http://www.initialrewards.com/)/Type/Action/S/URI
- http://www.exposedesigns.co.uk/)/Type/Action/S/URI
- http://www.symbiosis.co.uk/)/Type/Action/S/URI
- http://www.outstandinggirls.co.uk/)/Type/Action/S/URI
- http://www.chelseamodels.co.uk/)/Type/Action/S/URI
- http://www.ufi.org/)/Type/Action/S/URI
- http://www.aeo.org.uk/)/Type/Action/S/URI
- http://www.ncsevents.co.uk/)/Type/Action/S/URI
- http://www.messe-berlin.de/en/Visitors/ArrivalDeparture/Arrival/)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2016/ExhibitorManual/OrderForms/14.%20Stand%20Cleaning%20Order%20Form.pdf)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2016/ExhibitorManual/OrderForms/22.%20Parking%20Order%20Form.pdf)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2016/ExhibitorManual/OrderForms/15.%20Catering%20Order%20Form.pdf)/Type/Action/S/URI
- http://www.adexpo.nl/auto_inlog.php?afzender=g7Ahdk9fbxe)/Type/Action/S/URI
- http://www.igbaffiliatehotels.com/hotels.asp?id=3&idc=205&berlin)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2016/ExhibitorManual/OrderForms/16.%20Internet%20Order%20Form.pdf)/Type/Action/S/URI
- http://www.questbranding.com/)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2015/BAC2015_Water%20Installation.pdf)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2015/BAC2015_Waste%20Disposal.pdf)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2015/BAC2015_Compressed%20Air.pdf)/Type/Action/S/URI
- http://files.igamingbusiness.co.uk/Events/BAC2015/BAC2015_Gas%20Installation.pdf)/Type/Action/S/URI
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
- http://ns.adobe.com/illustrator/1.0/
- http://ns.adobe.com/xap/1.0/t/pg/
- http://ns.adobe.com/xap/1.0/sType/Dimensions#
- http://ns.adobe.com/xap/1.0/g/
- http://ns.adobe.com/pdf/1.3/
- https://protect-eu.mimecast.com/s/9XWzBHnkJgcA)/Type/Action/S/URI
- https://protect-eu.mimecast.com/s/GW47BUa0lVc1)/Type/Action/S/URI
Extracted artifacts 32
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0217_000.jsfefbea8a61fff6d2a5e8d7c764a407c92249644f8a10b0dec3cfae812883a2b7 |
pdf-javascript-stream | PDF /JS object 217 at offset 0x64E6C9 | 38 bytes |
javascript_obj0218_001.js572a91fc51702643df28955aaeeb86dd1625f4e3544ee1ba29446fcedc17c93d |
pdf-javascript-stream | PDF /JS object 218 at offset 0x64E817 | 41 bytes |
javascript_obj0412_002.js1b8b41f14847b9f918e2ad90f7e1b91033c18c338c9e29ca7ef10b8759190493 |
pdf-javascript-stream | PDF /JS object 412 at offset 0x651A87 | 39 bytes |
javascript_obj0432_003.js743fa30811b612e5269e980bb2fd29f8dbc72b45d4d461e89a455d2947561255 |
pdf-javascript-stream | PDF /JS object 432 at offset 0x651EA8 | 39 bytes |
javascript_obj0643_004.js685283849b5c17eba662c737cace366d122f01ffa301a043f32de564d5e1f017 |
pdf-javascript-stream | PDF /JS object 643 at offset 0x654E0A | 38 bytes |
javascript_obj0906_005.js57758ded0ac3700f786c45e29cca00842b712fb028ce95a4cd688d4f70c62fce |
pdf-javascript-stream | PDF /JS object 906 at offset 0x6580A5 | 33 bytes |
stream_087_off0016de35.bin0a1b4936115e6b328b85d2049f6456af5426c7cd36eddc69193ba10db592fb2a |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x16DE35 | 202552 bytes |
stream_091_off0019c97d.bin0cda0c093cddccd7fc84b95e466b44c99303f522467d05ffe80b8d87e196bfde |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x19C97D | 207576 bytes |
stream_107_off0020d4c4.bin89c67f232a674f795cf4dd5904bc231bc92a220664272061393e04b367192cb6 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x20D4C4 | 181648 bytes |
stream_114_off0022b42f.bin4567ffac80625c19b3cfce9afe44432abe080c4cf6368156d1cb599548dd5879 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x22B42F | 196780 bytes |
icc_00_off003730b1.icc2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
pdf-icc-profile | PDF ICC profile at offset 0x3730B1 | 3144 bytes |
icc_03_off0065bf9c.icc653b586c4707574ffcd648ba35494daed2c76ceafcf4c07d315ed961b1dc347f |
pdf-icc-profile | PDF ICC profile at offset 0x65BF9C | 408 bytes |
font_00_cff_off0002785d.bin17f1508b19406cf2e81f0b126a9b6cd6cdd2dceeb34ceb08170d257c61084552 |
pdf-font-stream | PDF embedded font (cff) at offset 0x2785D | 1414 bytes |
font_01_cff_off00027dd0.bin67563bcf4735f3ab815cf45c5fca5bea938c81a8274a42cbbd36ac318206e7ae |
pdf-font-stream | PDF embedded font (cff) at offset 0x27DD0 | 2626 bytes |
font_03_cff_off0025fb74.binf5e0204d1cde753158e839eec8a61cd3225fe7b6781c8b7e61ad6def2248c4d3 |
pdf-font-stream | PDF embedded font (cff) at offset 0x25FB74 | 2171 bytes |
font_04_cff_off0026078a.bin0bad5419524d3875da3456d14dddd136b529242cdc61cba20c21a2c71e250d96 |
pdf-font-stream | PDF embedded font (cff) at offset 0x26078A | 5064 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.42, consistent with packed or encrypted content.
|
|||
font_05_cff_off00261c07.bin5a98a93686f2ad89dcaf92db687702e95950b57ddf5d871c6fc7e125b1b4cc0a |
pdf-font-stream | PDF embedded font (cff) at offset 0x261C07 | 3204 bytes |
font_06_cff_off00262961.binec976f329a912d22464ebc4081f2b5c95bc57cc56306f15970e892832f483f39 |
pdf-font-stream | PDF embedded font (cff) at offset 0x262961 | 1964 bytes |
font_07_cff_off002be62f.bin8a00e2277a46607c20f711a74d97fa6682d7b18fbb6067b727937601050f1bd1 |
pdf-font-stream | PDF embedded font (cff) at offset 0x2BE62F | 2709 bytes |
font_08_cff_off002bf315.bin02a5e369cb27040f8c13cb4ccbf3425af1e3b3ca3bed5d244968af0f82c4dc41 |
pdf-font-stream | PDF embedded font (cff) at offset 0x2BF315 | 2140 bytes |
font_09_cff_off002bfd94.binbb028f56abc4dff7912cdbbbe59027b25b67254b321e8d351142f9c0aef827fd |
pdf-font-stream | PDF embedded font (cff) at offset 0x2BFD94 | 1919 bytes |
font_10_cff_off002c07e8.bin3b2f9581c94c15c96b484b0e89f83701496b856061206e07d10843f98cfa64d5 |
pdf-font-stream | PDF embedded font (cff) at offset 0x2C07E8 | 3689 bytes |
font_11_cff_off002c1877.bin0b2aeba9d581ac265f59f40ad5a409f27d6a3347981074e0f7006ac118953306 |
pdf-font-stream | PDF embedded font (cff) at offset 0x2C1877 | 3603 bytes |
font_12_cff_off002c287f.binadc2325c6f64ebeee19334d8bb82911dc701817a361a51663f174fdc74360a16 |
pdf-font-stream | PDF embedded font (cff) at offset 0x2C287F | 1821 bytes |
font_13_cff_off002c335b.bin755bd1edd327f64b04461589d9ac89c74383e9d29dc285052faa8ac70bfa115c |
pdf-font-stream | PDF embedded font (cff) at offset 0x2C335B | 5515 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.
|
|||
font_14_cff_off002f4871.bin4fe99f4d2408dd951c1b756608a7dc469c75199850967500045c5cded6ba9fc1 |
pdf-font-stream | PDF embedded font (cff) at offset 0x2F4871 | 1768 bytes |
font_15_cff_off002f52ca.binac18402ca6c6ee2a5424763f89e73c0bf5222bd8a2b9003442e1eddad64473ae |
pdf-font-stream | PDF embedded font (cff) at offset 0x2F52CA | 5106 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.43, consistent with packed or encrypted content.
|
|||
font_16_cff_off00322af5.bin9f6ddffe4f91070afae328ea73ee54728057743b454ba9f42d3fa95abe5e75f8 |
pdf-font-stream | PDF embedded font (cff) at offset 0x322AF5 | 1327 bytes |
font_17_cff_off00323316.bin5a3f52c7eafdec5d7c565a3af404dfce019944013b66c608cf61125cc6edf2f8 |
pdf-font-stream | PDF embedded font (cff) at offset 0x323316 | 3408 bytes |
font_18_cff_off003242b8.binc4ff9b8a8a0319bac91b7efb01f3e56824f885fcbe8ef6deaf98293ba1e6eac1 |
pdf-font-stream | PDF embedded font (cff) at offset 0x3242B8 | 3876 bytes |
font_19_cff_off003253a0.bin661b3204ab2733f5e0df690b2f6c7d014c2da200eaef085c450b85b285fca3b1 |
pdf-font-stream | PDF embedded font (cff) at offset 0x3253A0 | 1821 bytes |
font_20_cff_off00325e8f.binfff2d6315ac06cef6704a59bd1756c255b703d2c043a82895249fa5522df9068 |
pdf-font-stream | PDF embedded font (cff) at offset 0x325E8F | 5736 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact entropy is 7.42, consistent with packed or encrypted content.
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.