MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document flagged as malicious by ML classifiers and ClamAV. It contains an embedded URL, 'https://pelibifir.ru/aws?utm_term=whirlpool+cabrio+washer+will+not+power+on', which is likely used to redirect the user to a phishing or malware-hosting site. The document body, though heavily obfuscated, appears to reference the URL's subject matter, suggesting a lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/aws?utm_term=whirlpool+cabrio+washer+will+not+power+on
- http://lolabarafusiru.iblogger.org/lesanivesuluketa.pdf
- https://cdn-cms.f-static.net/uploads/4414695/normal_6030e8a141f42.pdf
- https://cdn-cms.f-static.net/uploads/4449603/normal_602b2d4e4abed.pdf
- https://cdn-cms.f-static.net/uploads/4383698/normal_602b344e7be69.pdf
- http://walkover.me/christian_thermo_king_omahagyvjv.pdf
- http://devovonabukuzim.66ghz.com/is_white_gas_the_same_as_coleman_fuel.pdf
- http://wimudevereru.sportsontheweb.net/liliaceae_family.pdf
- http://vzroslyh.net/2006_american_buffalo_gold_coin_valueg3uap.pdf
- http://aslixan.com/gumasukozusulivobajisawi5wtq1.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://sotenuzalarabi.epizy.com/anatomy_and_physiology_2_lab_practical_test.pdf
- https://s3.amazonaws.com/lejivugeleguwod/edexcel_further_maths_gcse_revision_guide.pdf
- http://lilepav.rf.gd/mufab.pdf
- http://vebusatoro.atwebpages.com/29462107462.pdf
- https://s3.amazonaws.com/vuzotisenixava/bomag_120_spec_sheet.pdf
- https://s3.amazonaws.com/kozewuposoridil/plantronics_voyager_legend_firmware.pdf
- https://s3.amazonaws.com/vefagotoje/30943131670.pdf
- http://gefafeduvul.epizy.com/kovevanin.pdf
- https://s3.amazonaws.com/zunewidimem/63448339743.pdf
- http://bedekopezedegej.rf.gd/57654517283.pdf
- http://zujebagita.epizy.com/pipalebavojararodutotitek.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011e78.bind855b1fbda823e5ec187c39e69ba0f15cb9ca7b0fc703d67a148022fa16d5c11 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11E78 | 5264 bytes |
font_01_sfnt_off00013069.bind8fc0c6b3c60e81998c2de9f25f148c4f36e005b0e247a291c40b8d63ce40a7c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13069 | 11428 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.