MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains an embedded URI pointing to a suspicious domain ('ponafet.ru') which is likely part of a phishing lure, disguised as a tutorial download. The presence of multiple unknown URLs further supports a malicious intent to redirect users to potentially harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/award?keyword=adobe+premiere+pro+tutorial+pdf+download
- https://cdn.sqhk.co/vopovaroxamo/WgjEgZS/dictador_20_year_solera_rum.pdf
- https://cdn.sqhk.co/wevavagu/figBjeJ/77312283658.pdf
- http://netlysy.online/59582548783kc7en.pdf
- http://new-leggins.site/505120499832jfeq.pdf
- http://buloshnaya.site/15104058628e2trw.pdf
- http://biotringel.shop/chicago_manual_style_bibliography_generator8asyp.pdf
- https://cdn.sqhk.co/wujukipako/lgfx87S/candy_crush_saga_level_2454.pdf
- https://cdn.sqhk.co/bikegola/iceIHqC/calendar_2020_november_month.pdf
- https://cdn.sqhk.co/wefekoferu/IrhgL1k/widnes_vikings_score_2019.pdf
- https://cdn.sqhk.co/gewanunu/jc0p9so/melody_meaning_example.pdf
- https://cdn.sqhk.co/likafupat/igibgiP/82127193251.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/c3013c74-5ba6-44ac-b544-80469f3f6d6f/silent_knight_sk-5208_reset_code.pdf
- https://s3.amazonaws.com/dovulavavo/in_on_under_next_to_worksheet.pdf
- https://uploads.strikinglycdn.com/files/8285f993-9b52-4327-9144-18985a48dd3f/47246839754.pdf
- https://s3.amazonaws.com/tupofelasujewas/nejodisenojisigivami.pdf
- https://s3.amazonaws.com/banula/lakshmi_narasimha_ashtothram_in_telugu_download.pdf
- https://s3.amazonaws.com/purixifusipelid/32734099554.pdf
- https://uploads.strikinglycdn.com/files/cd00de4e-3521-470e-95b2-c87b89e96d8a/how_to_open_kenmore_elite_washer_door.pdf
- https://s3.amazonaws.com/zuguvoxoki/50672080383.pdf
- https://s3.amazonaws.com/wutogugej/89766459670.pdf
- https://uploads.strikinglycdn.com/files/216992be-4553-4a97-9a29-657bb9bfcfa7/rotakivuzasitibozedarofus.pdf
- https://s3.amazonaws.com/nisoxow/desh_bhakti_song_dj_mix_pagalworld.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000103a0.bine4c3767406b20698674a06cce0b61a0146266364f397dfbff318398fd5c33a16 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x103A0 | 5228 bytes |
font_01_sfnt_off00011560.bin429883cb296faafbc19293095decbd0dde71cf7ac27fac28424bfa0f5a9e25a2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11560 | 11536 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.