MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1204.002 Malicious File
T1566.002 Spearphishing Attachment
The PDF file contains an embedded URL that points to an executable file. The 'PDF_LAUNCH' heuristic indicates that the document is configured to launch an action, likely to download and execute the file from the provided URL. ClamAV detection further confirms the malicious nature of the file, identifying it as Pdf.Exploit.Agent-35541.
Heuristics 3
-
ClamAV: Pdf.Exploit.Agent-35541 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Exploit.Agent-35541
-
Launch action high PDF_LAUNCHPDF contains a /Launch action with an unresolved or extension-less target — treat as potentially dangerous
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://ac-trans.ru/exe/file.exeAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Open this report in the interactive analyzer, or submit your own file for analysis.