MALICIOUS
144
Risk Score
Malware Insights
MITRE ATT&CK
T1204.002 Malicious Link
T1059.003 Windows Command Shell
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains embedded JavaScript and multiple external URLs, with a critical heuristic indicating repeated invisible links designed to deliver a payload. The document body explicitly instructs the user to copy and paste commands into execution contexts like Run or PowerShell, and a specific URL points to a ZIP archive. This suggests a multi-stage attack where the PDF acts as a lure to download and execute a secondary payload.
Machine Learning
- Nyx PDF Classifier clean score 0.0305
Heuristics 5
-
Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LUREPDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
-
Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LUREDocument tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://darksidecrew.co/ PDF link annotation
- https://www.xup.in/dl,14882471/Anonym-im-Internet-mit-Tor-und-Tails.pdf/In PDF document text
- https://www.xup.in/dl,20102652/Tails2019-01-27-A4.pdf/In PDF document text
- https://files.giga-downloads.de/system/Cortana_deinstallieren.zipIn PDF document text
- https://technitium.com/tmac/In PDF document text
- http://kernsafe-totalmounter.softonic.de/In PDF document text
- http://www.gburner.com/online-help/virtual-drive.htmIn PDF document text
- https://www.perfect-In PDF document text
- https://github.com/bwalex/tc-playIn PDF document text
- https://html2pdf.com/files/m82vytwnkvxneqb8/o_1e85lnbv4ir61lls1356h971us2b/Darksidecrew.co%20-%20Freiheit%20ist%20das%20Recht%20auf%20Anonymit%C3%A4t%20v1/download/user.jsIn PDF document text
- https://www.proxifier.com/download/In PDF document text
- https://vip72.com/In PDF document text
- https://www.darksidecrew.coIn PDF document text
- http://www.monotype.comMonotypeIn PDF document text
- http://www.monotype.comHowardIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://winfuture.de/downloadvorschalt,1329.htmlIn PDF document text
- https://de.wikipedia.org/wiki/Advanced_Encryption_StandardIn PDF document text
- https://de.wikipedia.org/wiki/TwofishIn PDF document text
- https://de.wikipedia.org/wiki/RIPEMD-160In PDF document text
- https://de.wikipedia.org/wiki/Serpent_In PDF document text
- https://www.veracrypt.fr/en/Home.htmlIn PDF document text
- http://mhogomchungu.github.io/zuluCrypt/In PDF document text
- https://de.wikipedia.org/wiki/Device_MapperIn PDF document text
- https://de.wikipedia.org/wiki/Ext4In PDF document text
- https://de.wikipedia.org/wiki/Einh%25C3%25A4ngepunktIn PDF document text
- https://www.mozilla.org/en-US/firefox/organizations/all.htmlIn PDF document text
- https://addons.mozilla.org/de/firefox/addon/ublock-origin/In PDF document text
- https://addons.mozilla.org/de/firefox/addon/uaswitcher/In PDF document text
- https://developers.whatismybrowser.com/useragents/explore/operating_system_name/android/In PDF document text
- https://addons.mozilla.org/de/firefox/addon/noscript/In PDF document text
- https://www.perfect-privacy.com/downloads/Perfect-Privacy-VPN_Setup.exeIn PDF document text
- https://www.perfect-privacy.com/downloads/Perfect-Privacy-SSH_Setup.exeIn PDF document text
- https://www.perfect-privacy.com/downloads/updown.shIn PDF document text
- http://www.monotype.com/html/mtname/ms_arial.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
- http://www.monotype.com/html/mtname/ms_couriernew.htmlhttp://www.monotype.com/html/mtname/ms_welcome.htmlhttp://www.monotype.com/html/type/license.htmlIn PDF document text
- http://tug.org/fonts/licenses/GUST-FONT-LICENSE.txtIn PDF document text
- http://fontawesome.ioIn PDF document text
- http://fontawesome.io/license/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_004_off00000628.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x628 | 10125 bytes |
SHA-256: 17f8f8a048868f75b24158c856a94ca90ec0693e7d89b82f91087447e045bf1f |
|||
stream_079_off0017f9d7.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x17F9D7 | 1064385 bytes |
SHA-256: 5551311b280d3d4c143e3dcf53c0417e8bb371f969ff4e7b2103fa1a62d219ac |
|||
stream_119_off001d78d5.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1D78D5 | 16604 bytes |
SHA-256: 22e3849e7f8a1ac64cbc848671cb67ce054c4b0f98dfb0d746f40fbe6258212c |
|||
font_01_sfnt_off001da825.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1DA825 | 10744 bytes |
SHA-256: 4a844010f4aba4f4834981df2e5c7e7261a414a52025b63280f8cad863b14af4 |
|||
font_02_sfnt_off001dc3d6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1DC3D6 | 15596 bytes |
SHA-256: cc613d23deb3d4e2930b42f0f97775d97bd275c91fc929fcfd07209004ea41d1 |
|||
font_03_sfnt_off001deecd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1DEECD | 7592 bytes |
SHA-256: 5ae7e8a0d3a2ff11caff4bdf32ec7c3db9965b65e955d7ffc4e0f66355d1deea |
|||
font_04_sfnt_off001e0024.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E0024 | 1996 bytes |
SHA-256: 6085e52fe09c1d91628623df19eab47409e96f447a3b09858de96303cedc90de |
|||
font_05_sfnt_off001e08ee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E08EE | 4648 bytes |
SHA-256: d248493dfd90e1ca20090324cbd4def1989c8888b455155da8afcfdd1594f892 |
|||
font_06_sfnt_off001e18c7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E18C7 | 3376 bytes |
SHA-256: ebd992dbe39ecad58c8cba434ee9ac77460270b966bb336e6795ba751f2015fc |
|||
font_07_sfnt_off001e23bd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E23BD | 22328 bytes |
SHA-256: 4fe76ea16df703bf76cc025ee5ed23641eb5001356fdbbdf9d9dca44983ac486 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.