MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains multiple invisible and repeated links designed to trick the user into downloading a payload. The primary malicious URL identified is https://leonvi.ru/123?utm_term=jacquie+lawson+cards.com, which is associated with payload delivery. While no scripts were explicitly extracted, the PDF structure and the presence of embedded URLs strongly suggest a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LUREPDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/123?utm_term=jacquie+lawson+cards.com In PDF document text
- https://cdn.sqhk.co/gufezitaxato/dOhhhfQ/smart_bomber_bomber_friends_apk.pdfIn PDF document text
- https://cdn.sqhk.co/vawapisoxe/hjChbhf/ice_cream_shops_near_delray_beach.pdfIn PDF document text
- https://cdn.sqhk.co/diwiporeb/Iihih2a/trading_neon_black_scooter_adopt_me.pdfIn PDF document text
- https://cdn.sqhk.co/kimamena/0CvihWp/drawing_charades_online_game.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4418984/normal_5fd635e221b52.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4447098/normal_5fc862d5b8b4d.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4405642/normal_5fe3232b61494.pdfIn PDF document text
- https://cdn.sqhk.co/fasotaluvose/ibiiqhj/rush_rally_3_switch_review.pdfIn PDF document text
- https://cdn.sqhk.co/wavefekus/IhgIGgh/70279019496.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4403563/normal_5ff758ada45c0.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/vitelitubovuluj/87774069777.pdfIn PDF document text
- https://s3.amazonaws.com/timituvupame/45675090436.pdfIn PDF document text
- https://s3.amazonaws.com/xalasawu/butterfly_valve_catalogue.pdfIn PDF document text
- https://s3.amazonaws.com/xajowu/rorerimodu.pdfIn PDF document text
- https://s3.amazonaws.com/sagotomagin/cartoon_app_for_android_free.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://www.jacquielawson.com/?source=jlfb&utm_source=facebook&utIn PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000150d6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x150D6 | 5324 bytes |
SHA-256: 7d0920c636c041ac5345df542646783c736b3a03a746e0b87f1808f358e55f74 |
|||
font_01_sfnt_off000162e9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x162E9 | 10780 bytes |
SHA-256: ac0713a09cdeec922b9b85f104569e5b9490098369128856a8d694bcf9dfd246 |
|||
font_02_sfnt_off00018703.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18703 | 16068 bytes |
SHA-256: 03a5ddad4a2a9171a93ce60914583e3601ab986f29a2c4cb248efc8e19c0a50a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.