MALICIOUS
170
Risk Score
Malware Insights
MITRE ATT&CK
T1203 Exploitation for Client Execution
T1566.001 Spearphishing Attachment
The PDF file contains an OpenAction trigger and a Launch action that attempts to open the URL www.google.com. While the URL itself is benign, the presence of these actions indicates an attempt to execute external content, a common technique for malware delivery. The ML classifier also strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 3
-
Launch action critical PDF_LAUNCHPDF contains a /Launch action whose target is an executable, URL, or UNC path — can start an external application
-
OpenAction trigger high PDF_OPENACTIONPDF has an /OpenAction that launches, submits, or opens an external target
-
/Launch action target: www.google.com high PDF_LAUNCH_COMMANDPDF /Launch action specifies an executable target.
Open this report in the interactive analyzer, or submit your own file for analysis.