MALICIOUS
134
Risk Score
Malware Insights
MITRE ATT&CK
T1059.003 Windows Command Shell
The PDF contains a high number of streams, suggesting obfuscation or heap spraying techniques. The document body mentions 'Sliver C2', indicating potential command and control activity. A key heuristic indicates a 'Password-protected archive handoff', suggesting the document is a lure to obtain a password for a malicious archive. The presence of 'curl https://' in the document text points to the potential use of command-line tools for downloading further payloads.
Machine Learning
- Nyx PDF Classifier malicious score 0.7150
Heuristics 5
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Unusually high stream count medium PDF_MANY_STREAMSPDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://github.com/BishopFox/sliver
- https://github.com/BishopFox/
- https://sliver.sh/install
- https://github.com/BishopFox/sliver/wiki/Port-Forwarding
- https://github.com/BishopFox/sliver/releases/tag/v1.1.0
- https://github.com/sliverarmory/armory
- https://github.com/skelsec/pypykatz
- https://github.com/GhostPack/Rubeus
- https://github.com/gentilkiwi/mimikatz
- https://adsecurity.org/?p=1729
- https://github.com/salesforce/jarm
- https://blog.cobaltstrike.com/2020/12/08/a-red-teamer-plays-with-jarm/
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90008
- https://www.cybereason.com/blog
- https://www.cybereason.com/blog/category/all
- https://www.cybereason.com/blog/category/research
- https://www.cybereason.com/blog/category/podcasts
- https://www.cybereason.com/blog/category/webinars
- https://www.cybereason.com/blog/category/resources
- https://www.cybereason.com/blog/category/videos
- https://www.cybereason.com/blog/category/news
- https://www.cybereason.com/
- https://www.cybereason.com/request-a-demo
- https://attack.mitre.org/tactics/TA0011/
- https://attack.mitre.org/tactics/TA0002/
- https://attack.mitre.org/techniques/T1059/003/
- https://attack.mitre.org/tactics/TA0004/
- https://attack.mitre.org/techniques/T1548/002/
- https://attack.mitre.org/techniques/T1134/
- https://attack.mitre.org/tactics/TA0005/
- https://attack.mitre.org/techniques/T1055/
- https://attack.mitre.org/tactics/TA0008/
- https://attack.mitre.org/techniques/T1569/002/
- https://attack.mitre.org/techniques/T1571/
- https://attack.mitre.org/techniques/T1090/
- https://www.ncsc.gov.uk/files/Advisory%20Further%20TTPs%20associated%20with%20SVR%20cyber%20actors.pdf
- https://www.proofpoint.com/uk/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity
- https://www.proofpoint.com/us/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity
- https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control
- https://en.wikipedia.org/wiki/DMZ_\(computing\
- https://0x00-0x00.github.io/research/2018/10/31/How-to-bypass-UAC-in-newer-Windows-versions.html
- https://www.wireguard.com/
- http://attack.mitre.org/techniques/T1548/002/
- https://attack.mitre.org/techniques/T1218/003/
- https://attack.mitre.org/techniques/T1550/003/
- https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a/
- https://ti.defender.microsoft.com/articles/b1406335
- https://www.cybereason.com/blog/ttp-briefing-q4-2025
- https://www.cybereason.com/blog/fake-installer-valleyrat
- https://www.cybereason.com/blog/identity-beyond-2026-incident-response-predictions
+30 more URL(s)
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_005_off00024cca.bin5f2661b34e824f9e1da534a831db6cc80a941154eaeeb01516400a5085330574 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x24CCA | 2260800 bytes |
icc_00_off0000019d.iccd9f822e8083f2f4d1c91e887454be5f75e8c7144b2853408f361e3c4a7a6b36d |
pdf-icc-profile | PDF ICC profile at offset 0x19D | 536 bytes |
font_00_sfnt_off00eafa86.bine662f4c2cecc22b66c4a2829360aebf8eb16b181bb8fe7ad5c8d548986165de3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEAFA86 | 4984 bytes |
font_01_sfnt_off00eb0d1d.bina64128ad1f51e291e4bb00da85865a3fe3ba13f62461398b0d0933cf4d7375fa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB0D1D | 8336 bytes |
font_02_sfnt_off00eb238d.bin61b4ab50c48bc1645cd9927de78b591c0231a247606027800341e09d23c5e138 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB238D | 8936 bytes |
font_03_sfnt_off00eb3492.bin67fd053778864a622fa421c337ef48f6cd900de5e4efb9c313c5f8cd410513f2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB3492 | 5988 bytes |
font_04_sfnt_off00eb4665.bincb4fe820dcb743931fe792c3df82c37f3d7bdc55c520acc8bdc53f5b61a41f8b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB4665 | 5404 bytes |
font_05_sfnt_off00eb98d7.bin5ad2bd21c9b16a4ba02bd7432dd474247eed8c39081c5ba103f8221e2d7d6e78 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB98D7 | 3712 bytes |
font_06_sfnt_off00eebf16.binef15a1c6e955d84dd750deafb6a10417fc173377250e7aec6c2b18590b1bee46 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEEBF16 | 3624 bytes |
font_07_sfnt_off00eff533.bindded656c451ef444c7effbc327b878f11302a295f7e2f2c9d51a177f46746881 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEFF533 | 2324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.