MALICIOUS
74
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The sample is a PDF document that impersonates a cloud document lure, aiming to trick users into clicking malicious links. It contains a heuristic indicating it is related to CVE-2023-26369 and uses XFA forms, suggesting exploitation of PDF vulnerabilities. The embedded URLs point to suspicious domains, likely serving as the initial stage for a multi-stage attack.
Machine Learning
- Nyx PDF Classifier clean score 0.0243
Heuristics 6
-
TrueType bitmap font + active content — CVE-2023-26369 related high PDF_CVE_2023_26369_RELATEDPDF embeds a TrueType font with bitmap tables (EBDT/sbix/CBDT) alongside exploit delivery indicators — CVE-2023-26369 exploits the sfac_GetSbitBitmap function in Adobe's libCoolType for arbitrary code execution. This CVE was actively exploited in the wild, but this rule does not validate the malformed EBLC/EBDT primitive.
-
Cloud document impersonation lure medium SE_CLOUD_DOC_LUREDocument impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://conchislandphotography.com/.%40.%40.%40.%40/.%40.%40.%40.%40?%7blink%7d&kjhgdhj=%7bdomain%7d&sdfg=iuyu
- https://earthholding.com/jhdjhdjhd/
- https://maderamundial.com/*@_@@@@@@@@@@/*@@@@@@@_@@@@@@@
- http://www.w3.org/1999/xhtml
- http://www.xfa.org/schema/xfa-data/1.0/
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/pdf/1.3/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://www.aiim.org/pdfa/ns/extension/
- http://www.aiim.org/pdfa/ns/property#
- http://www.aiim.org/pdfa/ns/schema#
- http://www.aiim.org/pdfa/ns/id/
- http://www.microsoft.com/typography/ctfontshttp://lucasfonts.comMicrosoft
- http://en.wikipedia.org/wiki/MIT_License
- http://www.microsoft.com/typography/fonts/default.aspx
- http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
- http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
- http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
- http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
- http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
- http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0��
- http://www.microsoft.com/pkiops/docs/primarycps.htm0@
- http://www.microsoft.com/Typography
- http://www.iec.ch
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_004_off0001cdc1.bin6ab6d176503e3398d59a98d998d70a97f18813a6a0f4e34d1eb4cd1576aebf08 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1CDC1 | 115244 bytes |
stream_005_off0002755c.bin706c99981821fc3e23150c8e689bcd6b88718515d8065081f8fab144b4786eb3 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x2755C | 101888 bytes |
icc_00_off000389a8.iccf02b2ee205805857ca2466141f69defb7f00c29e3ab1ee6695893df0aa65d7b1 |
pdf-icc-profile | PDF ICC profile at offset 0x389A8 | 3920 bytes |
icc_04_off0003eee2.icc2b3aa1645779a9e634744faf9b01e9102b0c9b88fd6deced7934df86b949af7e |
pdf-icc-profile | PDF ICC profile at offset 0x3EEE2 | 3144 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.