MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to 'zajinet.ru', which is likely a phishing or malware distribution site. The document body, though heavily obfuscated, suggests a lure related to a 'recipe book'. No scripts were extracted, but the PDF structure and embedded URI are strong indicators of malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=the+reboot+with+joe+juice+diet+recipe+book+pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/4dcecd0d-3f31-4b3f-a45a-f012be4b1c81/48444969164.pdf
- https://uploads.strikinglycdn.com/files/0e9224f6-8e86-4644-b110-04251b1120ac/mupowebigupulagaxo.pdf
- https://uploads.strikinglycdn.com/files/4d7a2915-34a7-446b-98df-d577a5562466/17569495273.pdf
- https://uploads.strikinglycdn.com/files/2e4446b3-7c8a-4b04-b7a3-9c4d26879d68/45566518087.pdf
- https://uploads.strikinglycdn.com/files/59dfe81e-2407-497b-9354-7cd1e835b03b/lizizavoxilami.pdf
- https://s3.amazonaws.com/dapekufoxiraku/specific_learning_disabilities.pdf
- https://uploads.strikinglycdn.com/files/948b4360-c0b2-496d-9122-9b74dd21071a/rebof.pdf
- https://uploads.strikinglycdn.com/files/7ad13d84-2f3e-42e9-95f8-fd066bde0bb9/thank_you_mr._falker_lesson_plan.pdf
- https://s3.amazonaws.com/sewamos/donotapodopedetofol.pdf
- https://s3.amazonaws.com/xotomisen/34771636652.pdf
- https://s3.amazonaws.com/tevigotu/what_can_adobe_acrobat_standard_2017_do.pdf
- https://s3.amazonaws.com/gofilafixu/wisawimavo.pdf
- https://uploads.strikinglycdn.com/files/dc48ff2d-2b52-4b0a-8e73-5554cb4b54d7/pippi_longstocking_movies_list.pdf
- https://s3.amazonaws.com/juliziwojatige/how_to_get_graphic_design_certificate.pdf
- https://uploads.strikinglycdn.com/files/30548594-8f3e-4546-a1fa-8495e5b2d5fc/35427872376.pdf
- https://uploads.strikinglycdn.com/files/d7371a85-260a-43e0-8ae6-ff661ff6e854/how_to_reset_a_honeywell_scanner.pdf
- https://s3.amazonaws.com/jobavo/dixoj.pdf
- https://s3.amazonaws.com/wegugus/linksys_connect_setup_software_wrt54g.pdf
- https://s3.amazonaws.com/nijudow/29936107207.pdf
- https://s3.amazonaws.com/tugabijenovili/garirasivofux.pdf
- https://s3.amazonaws.com/punagilelabon/22793689435.pdf
- https://s3.amazonaws.com/fidefofudi/deadpool_2_motion_picture_soundtrack.pdf
- https://uploads.strikinglycdn.com/files/847f1eae-a2e9-4bde-8488-185ea7b3e74f/91499996817.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011b68.bin26539a9f2bab631119f82c1cc452fc35c4eeb66213d1641edb22542361713ac8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11B68 | 5144 bytes |
font_01_sfnt_off00012cf7.bin8262ce5d8a94a0c5f9f4e179296782d73c32769efa1650f479a16e19db0945a6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12CF7 | 11524 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.