MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document flagged as malicious by ML classifiers and ClamAV. It contains an embedded URI pointing to a suspicious domain, 'ponafet.ru', which is likely used to host a phishing page or a second-stage payload. The document body is heavily obfuscated, preventing a clear understanding of its specific lure, but the presence of the malicious URL strongly suggests a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/strik?utm_term=central+and+peripheral+route+processing
- https://cdn-cms.f-static.net/uploads/4421224/normal_6067dbe394b7a.pdf
- https://cdn-cms.f-static.net/uploads/4378425/normal_60148bb34a378.pdf
- http://pajebunekelisom.22web.org/dovezukikimexita.pdf
- http://tofoxewesaxizuz.mywebcommunity.org/gajuxefoxiverix.pdf
- https://static.s123-cdn-static.com/uploads/4446491/normal_5fcee8cb74ab8.pdf
- https://cdn-cms.f-static.net/uploads/4384819/normal_6055477664556.pdf
- https://cdn-cms.f-static.net/uploads/4365649/normal_601cba5929c68.pdf
- https://static.s123-cdn-static.com/uploads/4445726/normal_5ffe0be58cc95.pdf
- http://jijoxep.getenjoyment.net/esl_appearance_worksheet.pdf
- https://static.s123-cdn-static.com/uploads/4475379/normal_5ff19d25d5d1b.pdf
- http://bamirajewenexo.medianewsonline.com/3d_in_powerpoint.pdf
- https://cdn-cms.f-static.net/uploads/4486521/normal_603d3f5f8838a.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/minegikukovel/d_d_5e_character_sheet_fillable_printable.pdf
- https://121f8fc1-d270-4171-a721-8ccd656fc20f.filesusr.com/ugd/2ca22b_d1233e8652b04062962ab32fc7ec2527.pdf?index=true
- https://ad9e3d1f-bb22-46ca-892e-b6aa3325a756.filesusr.com/ugd/837d34_08086f03ea214174918571eea6d9ac60.pdf?index=true
- https://748f1d53-d141-46c1-926a-d14fc69713a3.filesusr.com/ugd/e3ed1f_68d8762d239b4f278ed31554bcc7e0eb.pdf?index=true
- http://kazuzaj.epizy.com/62172628516.pdf
- https://s3.amazonaws.com/jufowokedunod/zivineritawebonijaxu.pdf
- https://s3.amazonaws.com/divexikav/tibuzaxisusanu.pdf
- https://s3.amazonaws.com/xilasisefi/original_dd_races.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011142.bin023486dbd5a153f87cd4743e81127fe84cda50b9e4e2e80ff52ac0f5fa220294 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11142 | 5240 bytes |
font_01_sfnt_off00012309.bin7a6872e821e0faa8819be02cee3741922fe5a0133cd6a78a02bd6daba781652f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12309 | 10544 bytes |
font_02_sfnt_off00014728.bin541fa2b6826b0add99b7d5a173ef1e6a5567607b5192f75b810eb17d6a563501 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14728 | 16204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.