MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an external URI pointing to a suspicious domain, and ClamAV detected it as a phishing trojan. The document body, though heavily obfuscated, appears to be a lure related to legal codes. The presence of embedded URLs and the ML classifier's high confidence suggest a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9956
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=what+is+the+texas+health+and+safety+code
- https://static.s123-cdn-static.com/uploads/4447466/normal_5ff2258ddb822.pdf
- http://jawazapefaxuzit.mywebcommunity.org/20398890802.pdf
- https://cdn-cms.f-static.net/uploads/4424689/normal_600a94a5129bd.pdf
- http://desokore.medianewsonline.com/sketchbook_brushes_free_download.pdf
- https://static.s123-cdn-static.com/uploads/4407994/normal_5ff7960a1971e.pdf
- http://legujepug.22web.org/autotable_jspdf_cdn.pdf
- https://cdn-cms.f-static.net/uploads/4403680/normal_5fda0dfcc19fb.pdf
- https://static.s123-cdn-static.com/uploads/4419626/normal_5fe02b6bea585.pdf
- http://saroforati.medianewsonline.com/dedineko.pdf
- https://static.s123-cdn-static.com/uploads/4382639/normal_6006242448228.pdf
- https://cdn-cms.f-static.net/uploads/4459630/normal_60604eee2653e.pdf
- https://cdn-cms.f-static.net/uploads/4371786/normal_5fd83ff60a5e4.pdf
- http://fesunasisodenod.getenjoyment.net/42073400308.pdf
- http://fegivate.medianewsonline.com/acid_base_and_electrolyte_chemistry.pdf
- http://buwovavozu.getenjoyment.net/8586736722.pdf
- http://vutunema.mypressonline.com/walmart_tv_65_inch_stand.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://misuxuji.rf.gd/pokemon_x_y_strategy_guide.pdf
- https://s3.amazonaws.com/gizonukorad/an_introduction_to_essential_algebraic_structures.pdf
- http://bilunet.rf.gd/waweselajenezikikukumadu.pdf
- http://zenowalu.rf.gd/camera_raw_filter_11._3_free.pdf
- http://rafesule.rf.gd/dolefa.pdf
- http://leparitupoxow.onlinewebshop.net/android_tutorial_tutorials_point.pdf
- https://s3.amazonaws.com/gogunabones/polidigililemojudorow.pdf
- http://mojogoralil.onlinewebshop.net/g_shock_rangeman_gpr_b1000_strap.pdf
- https://s3.amazonaws.com/kexamoxusinixu/alcatel_one_touch_flip_phone_a206g_manual.pdf
- https://s3.amazonaws.com/pujirageg/39670755943.pdf
- http://xogaduzop.atwebpages.com/scope_and_functions_of_wto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000df71.bin86ac504748b1d25367a79763cc514d07dffccee32bbb583ad34d458ce2c7a968 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDF71 | 5196 bytes |
font_01_sfnt_off0000f137.bind935d6bf80905990857698fb7852de3931853c605403a991bc76e596b1676285 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF137 | 10676 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.