MALICIOUS
140
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
This PDF contains an embedded file named 'info.doc', which is highly suspicious given the 'ML_NYX_PDF_MALICIOUS' and 'EXTRACTED_FILE_STATIC_TRIAGE' heuristics. The embedded file likely serves as a secondary payload, and the presence of an unknown URL suggests a potential download or command-and-control channel. The malformed stream length also indicates an attempt to obfuscate malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9100
Heuristics 5
-
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
-
Suspicious extracted artifact high EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTHA PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
-
Embedded file low PDF_EMBEDDEDPDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://copec.cf/bekkw83qccilyc64######################################################################################################################### In PDF document text
- http://schemas.openxmlformats.org/drawingml/2006/mainIn PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
info.doc |
pdf-embedded-file | PDF EmbeddedFile object 3 at offset 0x6A | 36864 bytes |
SHA-256: 18fe02e4ab29f2d79fdc9d17c3b921f7a5d1ca0be0287a5aa3d093f44f3f50df |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved macro source contains an auto-exec entry point and execution/download terms.
|
|||
Open this report in the interactive analyzer, or submit your own file for analysis.