MALICIOUS
176
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
T1059.007 JavaScript
This PDF file was flagged by a machine learning classifier and ClamAV as malicious. The 'ClickFix' heuristic indicates it's a social engineering attack designed to trick users into running commands, likely to download a secondary payload from the embedded URL. The 'Password-protected archive lure' suggests a common tactic to bypass initial security scans.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
ClickFix social engineering attack high SE_CLICKFIXDocument instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/123?utm_term=can+adobe+reader+xi+edit+pdf
- https://static.s123-cdn-static.com/uploads/4423430/normal_5fce8f5ea00b8.pdf
- http://wadupobem.iblogger.org/is_buying_penny_stocks_a_good_idea.pdf
- https://cdn-cms.f-static.net/uploads/4367268/normal_602f764254ae7.pdf
- https://cdn-cms.f-static.net/uploads/4366043/normal_60145855deb17.pdf
- https://cdn-cms.f-static.net/uploads/4401518/normal_6059b79e92c7e.pdf
- https://cdn-cms.f-static.net/uploads/4484093/normal_603ccfa676756.pdf
- https://static.s123-cdn-static.com/uploads/4484835/normal_5ff0e3ad189dd.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://xuzatazuji.epizy.com/madufemilotawizekir.pdf
- https://s3.amazonaws.com/farokof/zalowogaguwenep.pdf
- https://uploads.strikinglycdn.com/files/727be9fc-c786-4da1-be17-8e4ac47a8a09/punctuation_exercises_year_6.pdf
- https://s3.amazonaws.com/lefemijip/zenidokorekabanarotutekas.pdf
- http://pegagudebamu.epizy.com/how_to_pick_lock_with_pick_set.pdf
- http://webekilijonelew.epizy.com/descargar_netflix_para_android_7.pdf
- https://uploads.strikinglycdn.com/files/afabed92-69ad-4eaa-8bd3-c15d8288d155/89545524127.pdf
- http://xezexuro.epizy.com/bawetozawisor.pdf
- https://s3.amazonaws.com/nuxulikiwab/bruce_lee_workout_routine.pdf
- https://uploads.strikinglycdn.com/files/db2fcba5-c4a4-4d8c-8023-dfe799aa0826/what_causes_blood_spot_in_eye.pdf
- https://s3.amazonaws.com/zuses/my_talking_angela_2_game_apk.pdf
- https://uploads.strikinglycdn.com/files/90dc64b7-67f0-4409-b891-4bc748870e8d/soxederaw.pdf
- http://xuzezomitan.rf.gd/91698861522.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e9d4.bin842c1fb29f2134bf5c1896cc0e3a9ba499a6efc6b8ab1fd333a8278967ae7dce |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE9D4 | 4940 bytes |
font_01_sfnt_off0000faa6.binee13dab335ccfab5be8a8c64d0e59e405e2358b3919a361725f4d8640025d01a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFAA6 | 11796 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.