MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, which is likely used to deliver a secondary payload. The document body, though heavily obfuscated, suggests a lure related to 'collaborative problem solving approach pdf'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/award?keyword=collaborative+problem+solving+approach+pdf
- https://cdn.sqhk.co/linidivez/twhiahd/at_t_u-_verse_tv_u200_latino.pdf
- https://kawotubizon.weebly.com/uploads/1/3/1/8/131871780/nemozifunevuge.pdf
- http://waparudadip.mywebcommunity.org/werewolves_of_millers_hollow.pdf
- https://static.s123-cdn-static.com/uploads/4426541/normal_5fdf9a74f2ad7.pdf
- https://xizoxapuxuraxe.weebly.com/uploads/1/3/4/5/134598133/wobajanazuwesiv.pdf
- https://static.s123-cdn-static.com/uploads/4489850/normal_5ff3423607ff0.pdf
- http://supusatode.sportsontheweb.net/afrikaanse_verklarende_woordeboek.pdf
- https://cdn.sqhk.co/vexedobasof/fgjd9jc/73871008571.pdf
- https://vafarisitoguv.weebly.com/uploads/1/3/0/8/130874489/c4394ad.pdf
- https://static.s123-cdn-static.com/uploads/4377642/normal_5fcc939c5a0ad.pdf
- https://static.s123-cdn-static.com/uploads/4382627/normal_5fc7965793975.pdf
- https://cdn.sqhk.co/poxufape/ijghjjb/takeout_food_restaurant_near_me.pdf
- https://cdn.sqhk.co/xaselavub/gRtqhcO/refubizemevijepulixef.pdf
- http://virivuluk.getenjoyment.net/an_introduction_to_algebraic_structures_landin.pdf
- http://wutanumijejol.sportsontheweb.net/88927351526.pdf
- https://pabaxugu.weebly.com/uploads/1/3/2/6/132695470/bexoxisokix_duwudexaxon.pdf
- http://xonejalevesezom.sportsontheweb.net/gejala_cacar_air.pdf
- http://rusadezebep.mygamesonline.org/58678244428.pdf
- https://cdn.sqhk.co/tivanosox/ShfZid7/android_radio_car.pdf
- http://nemosixumeki.mypressonline.com/add_watermark_adobe_pro.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/4c77923f-3ff0-43ea-8a4d-501b748c0cc3/82795834157.pdf
- https://uploads.strikinglycdn.com/files/3a1d5168-4720-47db-80a0-4a7e8980d485/jiwexogepamakepoj.pdf
- https://uploads.strikinglycdn.com/files/56551eea-11e6-4079-900c-5e5123b858aa/semapa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ed74.bin29177abd2287e27d5a93fe4bf7d7031f54fc350a83e1f570a6f8b419d122a4de |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED74 | 5676 bytes |
font_01_sfnt_off00010095.bin593008cabc4258f8da900e763278622c44cf179af6fe7a42adea922b2905c417 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10095 | 10684 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.