SUSPICIOUS
42
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains numerous embedded URLs that point to various security and hacking-related websites, suggesting a lure to download further content. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic indicates the document is designed to instruct the user to open a password-protected archive, a common tactic to bypass security scanners. The presence of JavaScript streams further suggests potential malicious scripting capabilities.
Machine Learning
- Nyx PDF Classifier clean score 0.0004
Heuristics 2
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.visualbooks.com.br In PDF document text
- http://www.blackcode.comIn PDF document text
- http://www.hackerslab.org/eorg/fhz/proto.hIn PDF document text
- http://www.hping.orgIn PDF document text
- http://packetstormsecurity.orgIn PDF document text
- http://www.laurentconstantin.comIn PDF document text
- http://www.oxid.itIn PDF document text
- http://www.invasao.com.brIn PDF document text
- http://www.totalsecurity.com.brIn PDF document text
- http://www.securenet.com.brIn PDF document text
- http://www.digital-root.comIn PDF document text
- http://www.anti-trojans.cjb.netIn PDF document text
- http://www.nmap.orgIn PDF document text
- http://www.securityfocus.comIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/iX/1.0/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
🗂 Part of campaign:
hping.org
4 samples
Extracted artifacts 8
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_032_off0006b530.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x6B530 | 163836 bytes |
SHA-256: e71fc1263f9f0b5a89199186592540cb2c3863d827a3feb7b66ab86b1f281b94 |
|||
stream_043_off0008c68e.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x8C68E | 163836 bytes |
SHA-256: db999a66aeadc0c26fdee260a9e32a3c290f47e4dc6038b9ef9357c48a1d94d6 |
|||
stream_051_off0009cfcc.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x9CFCC | 163344 bytes |
SHA-256: 78e7f923e7cd39cf3309cf6a39392ef404052b916c91b3f8d527661d85dae47d |
|||
stream_052_off000a12b8.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xA12B8 | 163836 bytes |
SHA-256: 7c2ac715f35a31e9fd697e6e91d0647c5c83173a024e2f54350c3d16b1546d45 |
|||
stream_054_off000a7e50.js |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xA7E50 | 4931 bytes |
SHA-256: 0b32d4c14689e1fdbb87f32e19bcd4f6e626a8d8616da76be570c34c224630d2 |
|||
stream_081_off0011021a.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x11021A | 167328 bytes |
SHA-256: 694008f160c72b58d7779e649c3d119f8e2987f9265b6e5454a1556048a67bad |
|||
stream_137_off0017bae2.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x17BAE2 | 205176 bytes |
SHA-256: 4783f8e0243b4f7c40af941ba467923cdec468fb372b96b635d38d2e2b5e40ba |
|||
font_00_sfnt_off001beedb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1BEEDB | 4312 bytes |
SHA-256: 84ff96c12cb21985dbbfbb8c5aeca615e0fbc93fd78f612f90c346d4c0fe0fb3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.