MALICIOUS
144
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The sample is a PDF containing embedded JavaScript and external URLs, flagged by ML classifiers and ClamAV as malicious. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' indicates the document likely instructs the user to open a password-protected archive, a common tactic to bypass gateway security. The embedded JavaScript likely facilitates the download and execution of a secondary payload from one of the identified URLs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9985
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/wix?keyword=pic+basic+pro+manual+espa%25C3%25B1ol+pdf
- http://modozadubop.mywebcommunity.org/73876259902.pdf
- https://pavibizad.weebly.com/uploads/1/3/0/7/130740264/6474712.pdf
- https://lobavasato.weebly.com/uploads/1/3/1/4/131483685/8603547.pdf
- https://xejukosaxup.weebly.com/uploads/1/3/1/4/131437924/3170352.pdf
- https://jugusunoju.weebly.com/uploads/1/3/4/6/134625161/2bc25b0d.pdf
- https://wudigunufite.weebly.com/uploads/1/3/4/6/134611509/9930294.pdf
- http://wimobilo.iblogger.org/59641215662.pdf
- https://fusesekomufe.weebly.com/uploads/1/3/1/6/131606177/14ba77269090a.pdf
- http://tagaporigowekis.mygamesonline.org/45719183582.pdf
- https://jokilexagazoxo.weebly.com/uploads/1/3/4/6/134602179/2767339.pdf
- https://fumaletaseker.weebly.com/uploads/1/3/1/3/131381433/a288910190fd4af.pdf
- https://guvijubeb.weebly.com/uploads/1/3/5/3/135318684/2868835.pdf
- http://fowaxulop.iblogger.org/tesiv.pdf
- https://mizavujubamu.weebly.com/uploads/1/3/0/7/130775062/senisini.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/5eeb1ded-807b-45d7-a811-a1b2732e5ea4/how_many_players_can_play_joking_hazard.pdf
- http://kexetuleta.epizy.com/chinese_150cc_side_by_side_for_sale.pdf
- https://uploads.strikinglycdn.com/files/b85ad092-87bc-4678-8449-afb570c81eea/weber_grill_cooking_fish.pdf
- https://uploads.strikinglycdn.com/files/5cd5a4c6-757e-40bc-a2a3-8181442be90a/what_verse_says_all_things_are_possible_with_god.pdf
- http://futakanawus.onlinewebshop.net/sedimuxobofujazigaj.pdf
- https://uploads.strikinglycdn.com/files/30464a68-4ef6-4851-9268-788878fc2955/marketing_plan_definition_kotler.pdf
- http://luxupuxud.myartsonline.com/basic_bookkeeping_tutorial.pdf
- https://uploads.strikinglycdn.com/files/7cfb7d15-24f5-4f0b-8392-210bd14284b2/subdivision_meaning_in_english.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00029162.bin8dcc2a53f6122ca65fd7628ddd52e9ad9271aae879a507eee282702ebecabe1b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x29162 | 5652 bytes |
font_01_sfnt_off0002a436.bin5b83c1212116fb3518804901d134b47d385a54dc8a6410f9cd1055b2fb896d02 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2A436 | 13940 bytes |
font_02_sfnt_off0002d1db.bin541fa2b6826b0add99b7d5a173ef1e6a5567607b5192f75b810eb17d6a563501 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2D1DB | 16204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.