MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The PDF contains an embedded URL that directly points to an executable payload disguised as an ISO file. This heuristic, combined with other embedded URLs leading to executables, strongly suggests a malicious intent to deliver malware. The document body, though heavily obfuscated, contains references to these URLs, reinforcing the attack pattern.
Machine Learning
- Nyx PDF Classifier clean score 0.0014
Heuristics 2
-
PDF link points directly to executable/archive payload critical PDF_DIRECT_PAYLOAD_LINKPDF contains a clickable HTTP(S) URI whose path ends in an executable, script, shortcut, disk image, or archive extension. Documents can legitimately link to installers, so this is a high-risk delivery indicator rather than a standalone exploit fingerprint.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://download.tripy.be/iso/tripyv2.1.iso In PDF document text
- http://chilp.it/f91bb6In PDF document text
- http://www.tripy.eu/fr/tripy-2-gps-road-book-moto-route/produits/accessoiresIn PDF document text
- http://download.tripy.be/roadtracer/setuptripy_2_1_1_435.exeIn PDF document text
- http://community.tripy.eu/download/update/tripyupdate.exeIn PDF document text
- http://ocsp.verisign.com0In PDF document text
- http://www.daemon-tools.cc/fra/products/dtLiteIn PDF document text
- http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouIn PDF document text
- http://www.microsoft.com/typography/fonts/default.aspxIn PDF document text
- http://crl.microsoft.com/pki/crl/products/CSPCA.crl0HIn PDF document text
- http://www.microsoft.com/pki/certs/CSPCA.crt0In PDF document text
- http://crl.microsoft.com/pki/crl/products/tspca.crl0HIn PDF document text
- http://www.microsoft.com/pki/certs/tspca.crt0In PDF document text
- http://www.microsoft.com/typographyIn PDF document text
- http://www.microsoft.com/typography/fonts/YouIn PDF document text
- http://crl.verisign.com/ThawteTimestampingCA.crl0In PDF document text
- http://crl.verisign.com/tss-ca.crl0In PDF document text
- http://crl.microsoft.com/pki/crl/products/CodeSignPCA2.crl0OIn PDF document text
- http://www.microsoft.com/pki/certs/CodeSignPCA2.crt0In PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_006_off0001c9f6.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1C9F6 | 199656 bytes |
SHA-256: 530b2c38c0fcc58786a4cdf7128a9a8a7c5842ac792278ea9a661ec9a6a8f3df |
|||
font_00_sfnt_off000077c0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x77C0 | 182576 bytes |
SHA-256: cce8bf05d2ae560dd2f9f2f2de2fc90d810ee42e8cb98c74886ef000bedd82e4 |
|||
font_02_sfnt_off000341b3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x341B3 | 56804 bytes |
SHA-256: 15edbd3d172a16892dd83b7e90da0fd4fe04b430044012f42794d2fcdfd59297 |
|||
font_03_sfnt_off0003a513.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3A513 | 163020 bytes |
SHA-256: 3748e9e1f0b9b5d06ff551c592f5edb4247364a59bbf8ea3cee1043764135afa |
|||
font_04_sfnt_off0004cf51.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4CF51 | 35712 bytes |
SHA-256: 9dbcdcb5717c60423e002f3c52caa0e30181e0aee5f433997aeee96bab8b82b6 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.