MALICIOUS
116
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URL that leads to a domain associated with malicious activity, as indicated by the ML classifier and ClamAV detection. The 'SE_CALLBACK_LURE' heuristic suggests a phishing or tech-support scam pretext, aiming to trick users into visiting the provided URL. While no scripts were explicitly extracted, the PDF structure and embedded URI are strong indicators of a malicious intent to redirect users to a potentially harmful site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9033
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/wix?keyword=digimon+cyber+sleuth+digivolution+guide+pdf
- http://fabermanufacture.ru/90968710571zboy6.pdf
- http://sesizuxewewax.mygamesonline.org/fedex_locations_elkins_wv.pdf
- https://cdn.sqhk.co/bupabumo/iai8zlX/spqr_a_history_of_ancient_rome_book_review.pdf
- http://pivolirarorip.mypressonline.com/6453615672.pdf
- https://wuvobarapupi.weebly.com/uploads/1/3/0/8/130813490/wakipevameneze.pdf
- https://cdn.sqhk.co/tovipovo/hkgiPQm/zigzagoon_evolution_form.pdf
- http://goldotzyv.ru/why_would_my_kindle_not_turn_onhpyjm.pdf
- https://lepoxaxilil.weebly.com/uploads/1/3/4/4/134498836/2129355.pdf
- http://hookup757.fun/bsplayer_free_full_version_windows_7zjegu.pdf
- http://getbuiss.online/the_cambridge_history_of_warfare_geoffrey_parker6b59l.pdf
- http://leririv.sportsontheweb.net/how_to_charge_ion_tailgater_speaker.pdf
- https://suwuvonujijipi.weebly.com/uploads/1/3/4/0/134042364/bogabekuwir-rovifadus.pdf
- http://xoxuvajes.mywebcommunity.org/accounting_books_for_beginners.pdf
- https://woraragupawajup.weebly.com/uploads/1/3/2/6/132681931/daserazov.pdf
- http://salizurewaki.mypressonline.com/46574919266.pdf
- http://mjawebdesign.net/hermeneutics_principles_and_processes_of_biblical_interpretation1gu42.pdf
- http://jadogaxarabu.mygamesonline.org/72546434145.pdf
- https://mafaredoli.weebly.com/uploads/1/3/2/6/132695491/5305232.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://xijejuvi.myartsonline.com/what_is_the_toughest_sql_query_optimization.pdf
- https://uploads.strikinglycdn.com/files/d6c109e9-e595-4796-9ecc-acd5d449e790/48170459929.pdf
- https://uploads.strikinglycdn.com/files/821c3e27-0c60-4691-a173-118e1f27888f/dijewetudivubizugaj.pdf
- http://ritumogadoj.onlinewebshop.net/64870549832.pdf
- https://uploads.strikinglycdn.com/files/5cb0c58b-845c-4261-8823-038b61315eb1/documentary_letter_of_credit_cost.pdf
- http://felugibesixe.onlinewebshop.net/damn_good_friends_quotes.pdf
- https://uploads.strikinglycdn.com/files/197c81e7-c974-4fff-8fef-0b1c98979ba5/ladojorapususa.pdf
- http://dipagepe.atwebpages.com/pevotowibopimofoxokezufuv.pdf
- https://uploads.strikinglycdn.com/files/c0c08d41-7768-4766-a290-f6df7c079e0f/cavaliere_island_range_hood_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_009_off00052829.binec30b96a9371631b8343cf61a45d150560251d2bc9b319431286943cce65ee5d |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x52829 | 63240 bytes |
font_01_sfnt_off0005e457.bine85635c5a9d19f0a38fa24ec00c26950da4ad302d684d3918dab24b912173197 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5E457 | 5660 bytes |
font_02_sfnt_off0005f77d.bin568398b83649030462b603d7e6c18a3b6fdd23a86cb167bdaecaf4b0db8c1e84 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5F77D | 13240 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.