MALICIOUS
130
Risk Score
Malware Insights
MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious Link
T1566.002 Phishing: Spearphishing Attachment
The PDF file contains a launch action that directs the user to an external URL, indicating an attempt to exploit a vulnerability. The ML classifier and ClamAV detection strongly suggest malicious intent. The embedded URL is the primary indicator of a potential drive-by download or phishing attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9781
Heuristics 3
-
ClamAV: Pdf.Exploit.Agent-35541 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Exploit.Agent-35541
-
Launch action high PDF_LAUNCHPDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://globalstats.net/yes/load.phpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Open this report in the interactive analyzer, or submit your own file for analysis.