Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Phishing PDF with Unusual Hostname - SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Phishing PDF with Unusual Hostname

Taking a look with at a PDF received 2 days ago to update Amazon Prime account information:

This PDF contains /URI which might be of interest. Using, I generated some statistics (-a) like this:

And here I print the URL (/URI) in the pdf like this:

This hostname is a bit unusual, https[:]//903-63-845-845-matikaudekdek54yy4[.]com/l57kU89. I tried to get a copy of the suspicious file but the hostname was no longer resolving. The only information I was able to find about this hostname was from Domain State indicating that domain had already been deleted. No other cache or otherwise information available about this hosname.


Guy Bruneau IPSS Inc.
My Handler Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu


522 Posts
ISC Handler
May 2nd 2020

Sign Up for Free or Log In to start participating in the conversation!