MALICIOUS
118
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.002 Spearphishing Attachment
The PDF file is encrypted and contains JavaScript, indicating an attempt to conceal its true content and behavior. The presence of JavaScript actions and embedded JS streams suggests that the script is responsible for decrypting or executing the malicious payload. The PDF_IMAGE_ONLY_LURE heuristic suggests the document may be designed to trick users into interacting with it, possibly by presenting an image that requires further action. The combination of encryption and JavaScript points to a downloader or dropper mechanism.
Machine Learning
- Nyx PDF Classifier malicious score 0.9305
Heuristics 7
-
Encrypted PDF carries /JavaScript — payload hidden from static analysis high PDF_ENCRYPTED_WITH_JSPDF declares /Encrypt and also references an executable trigger (/JavaScript). Document encryption hides the JavaScript body and stream contents from static scanners — combined with auto-execution indicators this is a known evasion pattern used to deliver weaponised JavaScript that the analyst cannot inspect without the decryption key.
-
Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTHA PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
-
JavaScript action low 1 related finding PDF_JAVASCRIPTPDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
AcroForm button with action trigger low PDF_ACROFORM_BUTTONPDF contains a /Btn form field together with a SubmitForm/URI/Launch/JS trigger — this is the building block of fake 'Download' or 'Open' button overlays used in PDF phishing lures
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.monotype.comhttp://www.monotype.com/html/type/license.html In PDF document text
- http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATIONIn PDF document text
- http://www.iec.chIn PDF document text
🗂 Part of campaign:
shared payload 47a4c5a45e
3 samples
Extracted artifacts 13
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
javascript_obj0240_001.js |
pdf-javascript-stream | PDF /JS object 240 at offset 0x125B9 | 33 bytes |
SHA-256: f0a0eef79d820433b6742ba4c20f8407e0f3f78f2a827bda377f7690ca7578a1 |
|||
Preview scriptFirst 1,000 lines of the extracted script
AFDate_KeystrokeEx("mm-dd-yyyy");
|
|||
stream_086_off00024c66.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x24C66 | 5832 bytes |
SHA-256: 6cd6ccca5f401625bd8008aa506e350166d01a25a2a6041c290aecd55ca66e70 |
|||
stream_088_off00027368.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x27368 | 224990 bytes |
SHA-256: 47a4c5a45ebac005bd0066b3744f43dc55580d11b7befe7356e010c61617aa11 |
|||
icc_00_off00063ab2.icc |
pdf-icc-profile | PDF ICC profile at offset 0x63AB2 | 3144 bytes |
SHA-256: 2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
|||
font_00_cff_off00065e4d.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x65E4D | 465 bytes |
SHA-256: b2491543cd4dd3553cea63d439630a911d7677b34f488114c7c920379870962d |
|||
font_01_cff_off0006604a.bin |
pdf-font-stream | PDF embedded font (cff) at offset 0x6604A | 478 bytes |
SHA-256: 27549493b0b24d7ee752607e274118d549898e5cb23ee954964696937c7b44c5 |
|||
font_02_sfnt_off00066258.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x66258 | 46140 bytes |
SHA-256: 634cc1d35c4fab061064fb29367a39f2af073f6f48b6633217bb1660d52d7102 |
|||
javascript_obj0613_001.js |
pdf-javascript-stream | PDF /JS object 613 at offset 0x1E6EC | 33 bytes |
SHA-256: f35d13ad7cfb9d08f9063691ac68f9bb6db7c4b1fc10982e26c1015f500881e6 |
|||
Preview scriptFirst 1,000 lines of the extracted script
b ɹ�Nߜ�X����H���d )9Z��, �I�� K |
|||
javascript_obj0615_003.js |
pdf-javascript-stream | PDF /JS object 615 at offset 0x1E78D | 33 bytes |
SHA-256: 77c615245c0c1e3fbd9bcb51b51adbfd380cdd87d798764dd0a2f4875a05452d |
|||
Preview scriptFirst 1,000 lines of the extracted script
�C � gJ�h���Wߪ�-"W�5�c�@X�s%�B�� |
|||
javascript_obj0617_005.js |
pdf-javascript-stream | PDF /JS object 617 at offset 0x1E82D | 33 bytes |
SHA-256: 9ebd83527fc5baa85a3d7ba0eb865a0ff6bc6890ab7b1fd50390b027a32d3aa7 |
|||
Preview scriptFirst 1,000 lines of the extracted script
[� � ��ܓ2 +P� �`�A� �0�t3 UN�k� |
|||
javascript_obj0619_007.js |
pdf-javascript-stream | PDF /JS object 619 at offset 0x1E8CE | 33 bytes |
SHA-256: 07d229bd66cc7888bf99e9875e1c62f3f45d488f58f0a4945994ca596020c6a9 |
|||
Preview scriptFirst 1,000 lines of the extracted script
(� ���) � �d t�� ���X�0���̲: ~ |
|||
javascript_obj0007_009.js |
pdf-javascript-stream | PDF /JS object 7 at offset 0x20079 | 33 bytes |
SHA-256: 963cf2964f1b593e78c45184ea4fff28f0d869e066148b825abc925d50d1b884 |
|||
Preview scriptFirst 1,000 lines of the extracted script
���� ���qF� =����g �#&J�2��`��i�# |
|||
javascript_obj0156_084.js |
pdf-javascript-stream | PDF /JS object 156 at offset 0x2C7D2 | 33 bytes |
SHA-256: 9c68cb2e365e73e31ba51853b6810675bd0bd8e287d754485999e75eedf3dd7e |
|||
Preview scriptFirst 1,000 lines of the extracted script
� �� V��v{tn/h�T����-�^��*K��u���
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.