MALICIOUS
64
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The sample is a ZIP archive that contains a malicious PDF file. The PDF embeds multiple unknown-reputation URLs, suggesting it is designed to redirect the user to malicious websites. The presence of a malicious PDF within the archive indicates a likely spearphishing attachment delivery mechanism. The embedded URLs are the primary indicators of compromise.
Heuristics 3
-
Archive contains malicious member critical ARCHIVE_CHILD_MALICIOUSAt least one extracted archive member was classified as malicious. The archive is a transport wrapper for that payload.
-
Archive entry limit reached (50) info ARCHIVE_LIMITOnly the first 50 files were scanned.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://statsianighteworkes.com/info/nag3.html/n002106201r0409R2d0b805fXb9b2cb33Y06327c38Z0100f070 In document body
- http://qmyzued.info/cgi-bin/login.aspx/z00a106201r0013Rbfb3ec78Xbc6e663fY48d6c71eZ0100f070In document body
- http://beancountercity.in/cgi-bin/uiq/eH4c8bdea4V0100f055006R5bf734b4104T353528aa203l0019In document body
- http://atomisms.com//JHRD5oPT9-l.php/6d4df2d6d96b886e027e66e6769d6591?spl=pdf_2022In document body
- http://beancountercity.in/cgi-bin/uiq/eH74808a43V0100f060006R864c9f37104Tb45ac213201l0019In document body
- http://laryju.info/cgi-bin/qw/eH3fc7f49eV0100f060006R00000000102T6cdc8978201l0409In document body
- http://dbcavsaddve.com/nte/GNH4.php/eU230d9c2eH22e0fc05V0100f060006Re898a4e4102Tda6e7a7c203l000cK934985a1In document body
- http://www.jas.com/In document body
- http://googleinru.in/cgi-bin/etn/z002106201r0019Rde83fc65Xbc746ca9Y03e9fb2dZ0100f060In document body
- http://googleinru.in/cgi-bin/etn/z002106201r0019R5f8b8aaeXbcbd402dY16355bfeZ0100f060In document body
- http://beancountercity.in/cgi-bin/uiq/eH5efed755V0100f060006Re7cabfa8102T8d7626ed203l0019In document body
- http://estguard.com/cgi-bin/ca7/z002106201r0019R09bbe47dXca5583c3Y750a3e2cZ0100f060In document body
- http://93.174.93.11/~delmonca/u/load.phpIn document body
- http://networkget.com/cgi-bin/176/n002106201r0019Ra001e36bX48074092Y2759bc64Z0100f060In document body
- http://huil.in/x/exe.php?src=boss&id=&x=pdf4In document body
- http://searchfunes.org/cgi-bin/153/n002106204r0409Xb4a54ee8Y51edf563In document body
- http://googleinru.in/cgi-bin/etn/z002106201r0019Ra9018f30Xb47beff3Y53403b99Z0100f060In document body
- http://jlixup.info/cgi-bin/plt/eH1bc3362aV01001f50006R6ba960a6106Tc97c06a7201l0019In document body
- http://beancountercity.in/cgi-bin/uiq/eH649736beV0100f060006R3b3fb265106Tb45f01e7201l0019In document body
- http://bendigomarko.biz/cgi-bin/kln/z002106203r000cR47f2d04cXd50fb0c9Y7bd0f8afZ0100f060In document body
- http://geonetsa.com/cgi-bin/ca7/z002106201r0019R33a39b67Xbc0be973Y40a9b393Z0100f060In document body
- http://sazaw.info/page/hotweb.php/n002106201r0409Ra68ffd66Xb361d43eY4dd332d4Z0100f070In document body
- http://gotothefile.com/load.php?id=4In document body
- http://gotothefile.com/load.php?id=3In document body
- http://gotothefile.com/load.php?id=5In document body
- http://vgeohemef.info/cgi-bin/ae/eH0e035376V0100f060006R428e72bf102T96d0875e201l0019In document body
- http://beancountercity.in/cgi-bin/uiq/eH02cf7834V0100f060006R97f3b4e5102Tdae90089203l0019In document body
- http://state-mt.net/e/load.php?spl=pdf_newIn document body
- http://state-mt.net/e/load.php?spl=pdf_packIn document body
- http://ajxpeehuvpcv.com/nte/trest1.py/eH2acb515eV0100f060006Rf0096cc0102Tc4ba8cf7201l0019K5c531f23In document body
- http://beancountercity.in/cgi-bin/uiq/eH1b1f5403V0100f060006Ra89885e7102Tb43888ae201l0019In document body
- http://ajxpeehuvpcv.com/nte/TREST1.php/eH2de8defeV0100f060006R6d3429e9102T37231136201l0019K5f35201eIn document body
- http://adultxxxblog16.in//load445.php?spl=pd2_expIn document body
- http://erotic4gals.com/qw/l.php?i=8In document body
- http://click-reklama.com/cgi-bin/plt/z002106201r0019Rda58f754Xd7cd1e5eY154f9285Z0100f060In document body
- http://google.analytics.com.jvoamkvyxv.info/kav/kav1.php/eH6b91bb2fV0100f080006R50d5f875108Tb4454879201l0409Keca0c2c9In document body
- http://www.xfa.org/schema/xfa-template/2.5/In document body
- http://ns.adobe.com/xdp/In document body
- http://www.xfa.org/schema/xci/1.0/In document body
- http://www.xfa.org/schema/xfa-data/1.0/In document body
- http://www.xfa.org/schema/xfa-form/2.8/In document body
- http://ns.adobe.com/xtd/In document body
- http://ns.adobe.com/xfdf/In document body
- http://ow.ly/QdeV30gS3jLIn document body
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In document body
- http://ns.adobe.com/pdf/1.3/In document body
- http://purl.org/dc/elements/1.1/In document body
- http://ns.adobe.com/xap/1.0/In document body
- http://ns.adobe.com/xap/1.0/mm/In document body
- http://www.microsoft.com/typography/ctfontshttp://fontfabrik.comYouIn document body
+10 more URL(s)
Open this report in the interactive analyzer, or submit your own file for analysis.