MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URI pointing to a suspicious domain, identified by ClamAV as Pdf.Phishing.Trojan. The ML classifier also strongly indicated maliciousness. The embedded URL likely leads to a phishing site, attempting to trick users into downloading malware or providing credentials.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://krisoc.ru/pbw?utm_term=little+nightmares+1+download+android PDF link annotation
- https://static.s123-cdn-static.com/uploads/4407318/normal_60098d9513fe9.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4409113/normal_5fe6a26d958e6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4367286/normal_602e70ab52048.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4377379/normal_60beb0a9bb6a8.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4453329/normal_5feb56a11bc99.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4467912/normal_5fdf64ebc246d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4454984/normal_60bbb46da8dd5.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4391915/normal_6002e1a2bf744.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/56df0721-3b64-45c2-8cee-74b9d3029ef9/gebiw.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5fc25917-a06b-4e55-b6fa-09b8ccdd7454/what_colors_do_dachshunds_come_in.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/aa6c7a39-5dc5-49c8-b6eb-5cc12552dc08/sigma_906_switch_off.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/94e40f39-861f-4952-bf9e-6893c716c2a1/can_you_inject_ct_contrast_through_a_central_line.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/aed4b5c2-76bf-466c-8f6c-5098ed7426f7/samsung_galaxy_s8_fm_radio_apk.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bccf926b-2b3b-4c28-9480-d1136a363f5b/samsung_j2_pro_theme_store_apk.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/30018781-be98-46c0-b9dc-524e3095fbcb/4501605244.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/83c988b5-2da9-4382-9977-598a449e4a11/windows_10_for_free.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/15e082e4-c6fc-456d-ba81-5ab8fc066f59/kill_a_watt_ez_meter.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/022c3059-e1b9-4f40-8fb0-167620335b24/kemajatizobuz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/569ea65d-b47c-4999-9775-8297a5ff1ade/47530848476.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9907c537-5817-419c-aab7-17434fe21cb8/fomakata.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dd0e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDD0E | 5324 bytes |
SHA-256: 2c9d5d23f549533d2acc387dfb23a8bedd42f535d4f6cb306347d4395ad1ea43 |
|||
font_01_sfnt_off0000ef0d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEF0D | 10120 bytes |
SHA-256: 99b9f97a95f7ffb0eec4cfcaad8b99e2dc23473e96da07dfc21901fe928efc6d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.