MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. An external URI pointing to 'nomylo.ru' was extracted, which is likely the phishing destination. While no scripts were directly extracted, the PDF structure and the presence of a suspicious URL suggest a phishing attempt, possibly leveraging embedded JavaScript for redirection.
Machine Learning
- Nyx PDF Classifier malicious score 0.7341
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nomylo.ru/square?utm_term=i+wish+i+could+meaning+in+tamil
- https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f002e7c0b35f4fb3db01d2/1626342119520/tusiketumiwomubaz.pdf
- https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60e94d3d8ce0e10532d3f60b/1625902397209/xugigam.pdf
- https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ee0f74df274736e0a80264/1626214260368/73131608481.pdf
- https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e91348f107ff2467e87a27/1625887560493/introduction_to_sociology_short_answer_questions.pdf
- https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e915c20a287971af998c0f/1625888194240/how_to_put_text_boxes_on_a.pdf
- https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec82bae64ce5371634b970/1626112698425/12717472404.pdf
- https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f046c55d627c4551e69cfb/1626359493576/should_you_text_a_guy_that_ghosted_you.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000efb8.bincdd70fad1960937ebc25f964ad96d9fa9d634fe767438879fc422a23a072c253 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEFB8 | 16548 bytes |
font_01_sfnt_off000106d8.bin110d793d023085a7d791da0f825c4e9c704fac70528150faea904ba8a74fd561 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x106D8 | 17840 bytes |
font_02_sfnt_off00013617.binc2677658389c4d15093e5b99dbe314a01bfa4ac6e2f7058b8fbb6fc0c276423c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13617 | 10856 bytes |
font_03_sfnt_off00014ed5.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14ED5 | 16792 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.