MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document that contains an embedded URL, which is likely intended to redirect the user to a malicious website. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as a phishing trojan. The document body, though heavily obfuscated, suggests a lure related to a search query, aiming to trick the user into clicking the malicious link.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=orange+and+yellow+make+what+color
- https://cdn.sqhk.co/nivavepe/iajbrgd/95841982327.pdf
- https://cdn.sqhk.co/purilusevike/ehfnXCf/download_hi_q_mp3_recorder_apk.pdf
- https://cdn.sqhk.co/nesadatifu/gjGvA2n/ea_sports_ufc_4_career_mode_guide.pdf
- https://cdn.sqhk.co/kapipota/bkia2nT/73559678072.pdf
- https://cdn.sqhk.co/ritasuxa/vwbVTig/19239533748.pdf
- https://cdn.sqhk.co/xaloridinef/HPjbtjg/download_game_pocket_academy_zero_mod_apk.pdf
- https://cdn.sqhk.co/muvotugi/fYoifRD/goperisezumegenijexeko.pdf
- https://cdn.sqhk.co/fekawitaxug/YHii6Zt/rare_pokemon_cards.pdf
- https://cdn.sqhk.co/fazejitev/nidhdgf/pocket_city_free.pdf
- https://cdn.sqhk.co/dilizilozok/fhdiigh/hide_and_seek_game_no_download.pdf
- https://cdn-cms.f-static.net/uploads/4468823/normal_6017104f53278.pdf
- https://cdn.sqhk.co/dabozijide/gfiijf1/74527267564.pdf
- https://cdn.sqhk.co/dolafita/Sohhhgo/performing_arts_center_milwaukee.pdf
- https://cdn.sqhk.co/rasepotobami/ChsMggk/66065764676.pdf
- https://cdn.sqhk.co/goxepijikun/gdkfsw8/drivetime_cars_downey.pdf
- https://cdn.sqhk.co/lokalofobox/jb2UheV/kedatasiwidozimofetikasar.pdf
- https://cdn.sqhk.co/bozawenibiwa/jgyiehf/24428172164.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://juxugalipexobow.epizy.com/carlow_county_council_housing_application_form.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e405.bin3b3cd7ffa9a1d698ad502a9c439c0765f9f41f6d58b9e2d454ba555197be1f2e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE405 | 5460 bytes |
font_01_sfnt_off0000f680.bin274e099fd7b5b8aae7315c7faf0908795acb945599a9f7af7940fc6b738b3bf0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF680 | 10476 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.