MALICIOUS
74
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 JavaScript
T1566.002 Spearphishing Attachment
The PDF contains embedded JavaScript, including a call to eval(), which is a strong indicator of malicious intent. The extracted JavaScript streams, particularly 'javascript_obj0005_000.js', suggest obfuscated code designed to execute further actions. The presence of a mailto URI, while seemingly benign, could be part of a broader social engineering attempt. The overall pattern points to a malicious PDF designed to exploit vulnerabilities or trick the user into executing harmful code.
Heuristics 6
-
eval() call high PDF_EVALeval() found — commonly used for obfuscated exploit execution
-
JavaScript action low PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Optional Content Group with action trigger low PDF_OPTIONAL_CONTENTOptional Content Group (layer) co-occurs with an action trigger — content can be selectively hidden from viewers or scanners while the action still fires on open
-
External URI low PDF_URIPDF contains an external URL action
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0005_000.js1a4b81aeb35cc5aeea12e08cae8287ea3b03f29936f556b297be98a3edee5ca3 |
pdf-javascript-stream | PDF /JS object 5 at offset 0x2C2 | 82755 bytes |
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s).
|
|||
javascript_obj0005_001.jsf064e82e3d6230e2364b85613f671c59b6aa71549dcfbf96582dd07ee76a43c5 |
pdf-javascript-stream | PDF /JS object 5 at offset 0x2C2 | 630 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.