MALICIOUS
80
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
The PDF file contains embedded URLs, one of which uses a URL shortener (bit.ly). The ClamAV heuristic identifies this as a Pdf.Dropper.Agent, indicating it's designed to drop or redirect to malicious content. While the specific redirection target is not fully resolved due to the benign reputation of the bit.ly links themselves, the presence of a known dropper signature and the use of URL shorteners strongly suggest a malicious intent to lure the user to a harmful site.
Machine Learning
- Nyx PDF Classifier clean score 0.0004
Heuristics 3
-
ClamAV: Pdf.Dropper.Agent-7328912-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Dropper.Agent-7328912-0
-
Clickable URI uses URL shortener medium PDF_URL_SHORTENER_URIPDF contains a clickable HTTP(S) action whose destination is a URL shortener. This hides the final landing page from static review and is common in phishing redirect PDFs.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://bit.ly/2tkLNBQ
- http://bit.ly/2zE6mhV
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/pdf/1.3/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_004_off000057ab.binef0f7fc15ea0cd9d4439dbf95fb2c8e1452fa179b382733e9a703b8247cb0bfc |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x57AB | 198380 bytes |
stream_005_off0001c2a5.binfbd1542d1f330ffb194bf8450c425b7425f7268d39ce66ce0d160296b9cc3a3f |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1C2A5 | 300604 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.