SUSPICIOUS
42
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
The primary heuristic indicates this PDF is a lure for a password-protected archive, a common technique to bypass gateway security. The embedded URLs are benign and do not provide further clues. No scripts were extracted from this sample. The document body is heavily obfuscated and unreadable, preventing a more detailed analysis of its specific content or intent beyond the archive lure.
Machine Learning
- Nyx PDF Classifier clean score 0.0001
Heuristics 2
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://bazaar.abuse.ch/sample/6cf41e72620cafb1577415d626dbb66c8c796d7167164ca091a27c427337 In PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.