MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains an embedded URL that directs users to a page related to 'mxq pro android tv box firmware update', suggesting a phishing lure. While no scripts were explicitly extracted, the PDF structure and embedded URI heuristic indicate an attempt to redirect the user to a malicious site, likely for credential harvesting or further malware delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://wastran.ru/pbw?utm_term=mxq+pro+android+tv+box+firmware+update
- https://cdn-cms.f-static.net/uploads/4383160/normal_5fd1c94cd24a1.pdf
- https://cdn-cms.f-static.net/uploads/4469860/normal_605b7dd2d5e15.pdf
- https://cdn-cms.f-static.net/uploads/4381547/normal_6024294be2904.pdf
- https://static.s123-cdn-static.com/uploads/4404490/normal_5ff2349baa379.pdf
- https://cdn-cms.f-static.net/uploads/4384143/normal_601b444d1c5eb.pdf
- https://cdn-cms.f-static.net/uploads/4402519/normal_602117116b1d1.pdf
- https://cdn-cms.f-static.net/uploads/4415930/normal_604146de2b4e0.pdf
- https://static.s123-cdn-static.com/uploads/4423155/normal_5ffe473ad0ef7.pdf
- https://cdn-cms.f-static.net/uploads/4392877/normal_601ac4aa875b9.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://bupataved.pbworks.com/f/43358865799.pdf
- https://uploads.strikinglycdn.com/files/ba232519-a3d1-452a-9ca9-e41e42f00e0c/can_we_sleep_while_wearing_contact_lenses.pdf
- https://uploads.strikinglycdn.com/files/7bc7303e-4d09-412d-8820-1135235d7a34/the_ministers_black_veil_literary_analysis_essay.pdf
- http://rugewenuzed.pbworks.com/f/pelolufofoxivaxuvoseten.pdf
- https://uploads.strikinglycdn.com/files/82d9f3ac-4cf9-4f5c-a769-682507756c85/88038002263.pdf
- http://wuwazilizos.pbworks.com/w/file/fetch/144425397/presidents_choice_5_cup_coffee_maker_manual.pdf
- http://wuvebag.pbworks.com/w/file/fetch/144428589/how_to_bypass_beko_washing_machine_door_lock.pdf
- http://kedetuwi.pbworks.com/f/barry_windsor_smith_conan.pdf
- http://nowefuro.pbworks.com/f/materi_manasik_umrah.pdf
- http://kedetuwi.pbworks.com/w/file/fetch/144428070/8676377527.pdf
- http://zajozote.pbworks.com/w/file/fetch/144437205/rubapazozobomiposaru.pdf
- https://uploads.strikinglycdn.com/files/025b0556-d913-4d34-a934-99ed3f46f054/92642290746.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000109d4.bind82db9509c3f9497178aaf5d077583c943f3a8be3b205c610e411a3041f2a079 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x109D4 | 5468 bytes |
font_01_sfnt_off00011c72.bindaad3f347a4f42f432ee9983e619a7c063e36761dba5934b469418034847e28e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11C72 | 1800 bytes |
font_02_sfnt_off00012500.bina4e7c2811ffe0de4742bfa8a944e00cce1db0996c8e283480ff379ce98bd0189 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12500 | 10684 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.