MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of embedded URLs, some pointing to suspicious PDF files hosted on compromised websites, suggests a phishing or credential harvesting campaign. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to trick users into downloading further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://hoovermaids.com/wp-content/plugins/super-forms/uploads/php/files/25d866770d899d8c007fcff649ad69ea/98878891500.pdf
- https://www.goldenplanet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160948a6a75070---57129929863.pdf
- http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/h945ospgag1tpsuu3455qab3c7/samirunabunarinefenute.pdf
- https://jennysbooks.com/wp-content/plugins/super-forms/uploads/php/files/3a98a6ca68faa029ec414911fb2265ca/18317218141.pdf
- http://adamlegal.com/userfiles/file/demudizenapezilirigewurav.pdf
- http://gennarimaq.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608d7eaaefe54---puxapo.pdf
- https://dungcuruamui.com/wp-content/plugins/super-forms/uploads/php/files/f91bveahq9vpd731fqmp0vp6fb/wigugulexu.pdf
- https://gfow.om/wp-content/plugins/super-forms/uploads/php/files/93dj622k6ot6ds957hr1kq1iec/logifamiforagivutupi.pdf
- https://ltgtrends.com/wp-content/plugins/super-forms/uploads/php/files/1c9d268d53604521fec2d538b282916d/ragoforosa.pdf
- http://alpanelektrik.com/depo/sayfaresim/file/wukigapusi.pdf
- http://grupogmec.com/wp-content/plugins/formcraft/file-upload/server/content/files/160715bc47c526---gisupuxomiluzoloz.pdf
- http://blog.crowdly.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cdcd512ea1---wudivogusofowipaxuganafof.pdf
- https://elpmarketing.ca/wp-content/plugins/super-forms/uploads/php/files/feb9120b7adf00d7e873903f74605429/37181659694.pdf
- http://agendatourvietnam.com/hinhanh/file/14686208354.pdf
- http://www.viksexteriors.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607768a32095a---fosevowa.pdf
- https://mission4recruitment.com/wp-content/plugins/formcraft/file-upload/server/content/files/16094684fd1105---rezirorugonomadejorat.pdf
- https://costumeworld.com/wp-content/plugins/formcraft/file-upload/server/content/files/16085c04f845ac---74738323779.pdf
- http://apexibd.com/uploads/fck_uploads/file/60915611913.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=os+capit%25C3%25A3es+da+areia+pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e362.bin1e00b1d3046168d03c293da2233b8983301ecc3ff6a8030bbe72bf13ae5a648c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE362 | 5464 bytes |
font_01_sfnt_off0000f575.bincf0a25b87cefd1fc58490bb99974054847cb2a45331c07daa59365fc01db045a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF575 | 12036 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.