MALICIOUS
84
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file is identified as a malicious PDF dropper by ClamAV. The document body, though heavily obfuscated, contains indicators of a callback phishing lure, prompting the user to contact a phone number for a fabricated issue. An external URI was also extracted, likely part of the lure or payload delivery.
Machine Learning
- Nyx PDF Classifier clean score 0.0086
Heuristics 4
-
ClamAV: Pdf.Dropper.Agent-7226951-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Dropper.Agent-7226951-0
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://go2l.ink/desk091881
- http://ocsp.verisign.com0
- https://i.imgur.com/CuYHT2A.png
- http://www.microsoft.com/typography/ctfontshttp://lucasfonts.comMicrosoft
- http://en.wikipedia.org/wiki/MIT_License
- http://www.microsoft.com/typography/fonts/default.aspx
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
- http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
- http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
- http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��
- http://www.microsoft.com/pkiops/docs/primarycps.htm0@
- http://www.microsoft.com/Typography/0
- http://www.monotype.com/html/mtname/ms_symbol.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlNOTIFICATION
- http://www.monotype.com/html/type/license.html
- http://crl.verisign.com/ThawteTimestampingCA.crl0
- http://crl.verisign.com/tss-ca.crl0
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0O
- http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0
- http://www.microsoft.com/typography
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_002_off00003bcf.bin587d0410d048bb3568812dd8f80786cb54fcc2760faf0b0066a104dce91de133 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x3BCF | 372348 bytes |
font_00_sfnt_off00000687.binca6c494bb5ef9be7361cfad38425c9e5ec46bc51a29f0a9ed3e0b4866540a7f4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x687 | 24332 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.