CLEAN
24
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1027 Obfuscated Files or Information
The PDF is heavily obfuscated and encrypted, preventing static analysis of its content. Heuristics indicate it's an image-only lure with embedded URLs, suggesting a phishing or social engineering attempt. The high stream count further points to deliberate obfuscation. While the embedded URLs themselves are benign, the overall structure and encryption are highly suspicious.
Machine Learning
- Nyx PDF Classifier clean score 0.0005
Heuristics 3
-
Unusually high stream count medium PDF_MANY_STREAMSPDF contains 501+ stream objects — may indicate heap spray or heavy obfuscation
-
Encrypted PDF (string and stream contents are opaque to static scan) info PDF_ENCRYPTEDPDF declares /Encrypt — string objects and stream contents are encrypted with the standard security handler (RC4 or AES). On its own this is informational; legitimate encrypted documents include signed contracts, billing statements, and rights-managed material. Static heuristics cannot inspect encrypted payload bytes.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.