MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document that contains embedded URLs, some of which are flagged as unknown reputation. The ML classifier and ClamAV detection strongly indicate maliciousness. The document body, though heavily obfuscated, suggests a lure related to a 'Poodle size guide', which is likely a pretext to trick users into visiting malicious links for phishing or malware delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://auxerretv.com/content/public/file/37552050658.pdf
- https://smarttactic.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1608dff3b1548e---mesosetesibopo.pdf
- https://www.heainc.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075d2ebf3860---47131559847.pdf
- http://www.theflightfest.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608413fc862ae---mitisirelasev.pdf
- https://kfz-gutachter-oliver-schiller.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609411f34fa25---93224282072.pdf
- http://hzjksj.com/images/upload/File/77247354985.pdf
- https://absolut-fit-and-dance.de/wp-content/plugins/super-forms/uploads/php/files/g3gccotbgh8fi6dbbcbhjv7q2j/10094551574.pdf
- https://alphaveneers.co.uk/wp-content/plugins/super-forms/uploads/php/files/79102e7daa4ee7d75a19ad5e9c5c3876/wogaruvosixifijuxisodel.pdf
- https://vizzzio.ru/wp-content/plugins/super-forms/uploads/php/files/a2f01583013a5c2dd215e75bef8b7777/genokejuwerekadirukawetot.pdf
- https://www.traveltimevipp.com/wp-content/plugins/super-forms/uploads/php/files/313bb09ed0c77132e3cfd465b4a99cab/ximetuto.pdf
- https://www.sudburyhighspeedinternet.ca/wp-content/plugins/super-forms/uploads/php/files/9e3326e08cf109207398027306ddca2b/govimi.pdf
- https://studiogreenwich.ru/wp-content/plugins/super-forms/uploads/php/files/4737bafde7592ae5b9cf0ba8cc5890c3/22541150229.pdf
- https://oneremote.ru/wp-content/plugins/super-forms/uploads/php/files/65e8d10d3a60d2af8c7661d71d7dbbec/27795159060.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://feedproxy.google.com/~r/skout/mBVl/~3/FevRqgeaUVY/uplcv?utm_term=poodle+size+guide
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cbb4.bince2b180f0ce6eb68f56b5537175eb3f3263fec303576d0a01ff15eaf299f9ccb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCBB4 | 4436 bytes |
font_01_sfnt_off0000dacf.binb8c943a183c8dd8521ec4a244f92781da1a17a2dde909223fc720a7c4beb0120 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDACF | 9824 bytes |
font_02_sfnt_off0000fc6a.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC6A | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.