MALICIOUS
166
Risk Score
Malware Insights
MITRE ATT&CK
T1539 Steal or Forge Credentials
The PDF document contains heuristics indicating it's a phishing lure, specifically requesting recovery secrets or private keys from the user. It also contains a lure to execute commands via copy-pasting into a shell. The embedded URL points to a domain associated with malicious activity, further supporting the phishing and credential recovery intent.
Machine Learning
- Nyx PDF Classifier clean score 0.0055
Heuristics 6
-
Recovery secret / private key request critical SE_SECRET_RECOVERY_LUREDocument requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LUREDocument tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jottigo.ru/wix?keyword=isc2+sscp+study+guide+pdf
- https://cdn-cms.f-static.net/uploads/4486969/normal_60103e6e0b170.pdf
- https://fetuxugov.weebly.com/uploads/1/3/4/6/134655394/4224e5eff.pdf
- https://cdn-cms.f-static.net/uploads/4481275/normal_603448a3ef642.pdf
- https://cdn.sqhk.co/kataduzoni/B4pPhgp/posajogatawetirip.pdf
- https://cdn-cms.f-static.net/uploads/4415526/normal_602596b5ca97d.pdf
- http://sdfsdfsdf.shaketorch.com/kopanamifotivozuwu.pdf
- https://cdn.sqhk.co/xobupuwulawe/nhbkhdR/64858708607.pdf
- https://mivixotagu.weebly.com/uploads/1/3/1/3/131384173/mogujuk-kelomutanineg.pdf
- https://cdn-cms.f-static.net/uploads/4372972/normal_604f54a1515da.pdf
- https://lanasasaf.weebly.com/uploads/1/3/0/8/130815311/kifasepumobufazofa.pdf
- https://cdn.sqhk.co/xekawiba/5N9jegd/arma_3_zombie_mod_2020.pdf
- https://static.s123-cdn-static.com/uploads/4476268/normal_5feef92120fa0.pdf
- https://fezuwarojeti.weebly.com/uploads/1/3/1/3/131383544/vowuwadiliri-borumunodo.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/jaxesabi/countif_function_in_excel_across_multiple_sheets.pdf
- https://uploads.strikinglycdn.com/files/d90bdd87-b154-43e4-b217-b0dfe2a7a842/what_are_the_technical_questions_asked_in_interview_for_ece_students.pdf
- http://mafojupovovod.rf.gd/can_kindle_paperwhite_battery_be_replaced.pdf
- https://s3.amazonaws.com/lumixi/zasuxulixironob.pdf
- https://uploads.strikinglycdn.com/files/ebfad4c7-fd43-477e-8b26-6d2226378d4d/49138270627.pdf
- http://xupimegoroze.epizy.com/tamil_bible_dictionary_free.pdf
- https://uploads.strikinglycdn.com/files/dc306b46-dd6c-4fea-92af-0cde9bc7a9d3/links_awakening_review_reddit.pdf
- https://uploads.strikinglycdn.com/files/b956c253-91ee-4f98-90e5-144301786bcb/nelafisixerotixewimof.pdf
- https://uploads.strikinglycdn.com/files/620fd4b3-9dc6-48c5-abf0-84e3bacb71fb/difidululidufeb.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0019ad8c.bin90c8c2d8d4ee123e589433b49e7612f97a188c05cb3aeef0e0e47262bb58dd70 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19AD8C | 5156 bytes |
font_01_sfnt_off0019bf53.binc39f153cf02b0c6a95e472374070b376f19f346d17830df15e6b41cb4c0cb154 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19BF53 | 13664 bytes |
font_02_sfnt_off0019ec94.bind6f0d2c712a9045692733a59b6d57afe4462d8d3dca4016e6a89d0be585f12df |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19EC94 | 16204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.