MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document that contains a URL pointing to a phishing site. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically phishing. The embedded URL is the primary indicator of compromise, suggesting the document is a lure to direct users to a malicious website.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/strik?utm_term=wordly+wise+3000+book+5+lesson+9+quizlet
- https://cdn-cms.f-static.net/uploads/4377408/normal_603c65621f630.pdf
- http://dixagodal.iblogger.org/jojiwazarologesodi.pdf
- https://static.s123-cdn-static.com/uploads/4459774/normal_5fe4992fe20d8.pdf
- http://zovanatul.iblogger.org/play_the_game_movie_parents_guide.pdf
- https://cdn-cms.f-static.net/uploads/4457620/normal_60114a3b97966.pdf
- https://static.s123-cdn-static.com/uploads/4453336/normal_5ffa03a56c74e.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://zovoxasus.rf.gd/surah_al_mulk_dan_artinya.pdf
- https://1c2b20db-dbe1-4299-b4c0-f67d595d3b6c.filesusr.com/ugd/e71423_ef5f0d09992246c8816381044ea934ca.pdf?index=true
- http://demajipo.rf.gd/criticism_of_lewis_model.pdf
- https://uploads.strikinglycdn.com/files/d649fb2e-a75b-4e66-b326-bcda4a852bfa/que_es_un_proyecto_de_investigacion_tecnologica.pdf
- https://436c154b-1c2d-4c60-9768-ed3a268ef5e1.filesusr.com/ugd/e8e253_375810c1c7154b858c5a908723360db3.pdf?index=true
- https://uploads.strikinglycdn.com/files/c4b38d2d-5885-4c17-8ce3-a7353a1663a7/how_to_do_brazilian_jiu_jitsu.pdf
- http://teposowadu.rf.gd/fasefomoxilasosup.pdf
- https://804b95bc-9ca4-448d-a094-5a8e1ff69a26.filesusr.com/ugd/99d1da_05c8259e221e430ebc66b4b627dd6c03.pdf?index=true
- https://f187853a-68e6-4ed6-a420-9593b89d6738.filesusr.com/ugd/27c34a_67118e30ae4640e2bdf41b6dec45bc77.pdf?index=true
- http://dedumiwikos.epizy.com/57516693147.pdf
- http://gapisamiwabu.epizy.com/formica_sheets_for_kitchen_walls.pdf
- https://badbb018-ab4e-499b-b788-960949b82e3d.filesusr.com/ugd/4f4c56_ccc65f978cda4539977d77d53684c687.pdf?index=true
- http://sumoguvovubipil.epizy.com/android_developer_bluetooth_tutorial.pdf
- https://uploads.strikinglycdn.com/files/b20ea9b6-6db4-46ff-b94d-b9a696c4eed3/identidades_trigonometricas_cotangente_al_cuadrado.pdf
- http://burelagufepe.epizy.com/microcrystalline_cellulose_properties.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e551.bin8565cb8c7057c1458ab6adab7354e82c273a7703a0f3f45f0e9bd9d7780ca8f2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE551 | 5784 bytes |
font_01_sfnt_off0000f933.bin03b8822259464c1a2f4cebdf8249d4631fa6ada2fc79aa27a6dd1bc5246c4d7c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF933 | 11268 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.