MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The file is a PDF that was flagged by ClamAV as a phishing trojan and also by an ML classifier with high confidence. While the document body is heavily obfuscated and unreadable, the presence of embedded URLs and the overall detection suggest a malicious intent, likely to trick the user into downloading further malicious content. The 'SE_DOWNLOAD_BUTTON' heuristic further supports a lure-based attack pattern.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://feedproxy.google.com/~r/sq/ugae/~3/XMoLd4EPXkg/square?utm_term=how+to+get+battle+cats+hacked
- https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60edb0639a9df7051d4122f3/1626189923888/phrases_that_start_with_f.pdf
- https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e9064d0cbdad4d3504d25a/1625884237684/a_chemostat_is_also_known_as.pdf
- https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ee27afe9cbfe6c2fe6745c/1626220463890/itouch_users_manual.pdf
- https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60f832f6503e0e282bf71e48/1626878710302/powerpoint_file_history.pdf
- https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f1f0f57e0b8055ef707025/1626468599112/much_other_words.pdf
- https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60e795795eabb22f35d6992e/1625789817475/jeppesen_instrument_commercial_manual_free_download.pdf
- https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f66a1ec7777d0a4de7edb6/1626761758369/95374905452.pdf
- https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60e91e953ba7d954d54618d7/1625890453728/43636418092.pdf
- https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e9359c37cb90447560a03c/1625896348893/33983577589.pdf
- https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60e8e0ecc91b61347ea03b9d/1625874669057/92524191552.pdf
- https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f4cd9dc4d0d61e67495e9e/1626656157502/scala_for_the_impatient.pdf
- https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f934ac871fd428ad90f631/1626944684868/bully_geography_5.pdf
- https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ee86966d75c50a5d47d632/1626244758962/jinevoju.pdf
- https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f6c01e72e43e21e354df37/1626783774442/avatar_the_last_airbender_ds_rom.pdf
- https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60fa5b62d6e5825ac4e041e9/1627020131040/kebok.pdf
- https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60f77fdb53df297156b17419/1626832860001/tapamowonom.pdf
- https://static1.squarespace.com/static/60aac59fb7e9621e2f466549/t/60f474c70dbab00e46ee77d3/1626633415314/fill_me_with_your_poison.pdf
- https://static1.squarespace.com/static/60bf6c89a2b0b938881bcf91/t/60ec918e97282d6f46916c32/1626116494358/tixafaberefeneleguw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ef5e.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEF5E | 16792 bytes |
font_01_sfnt_off00010775.bin8c037be97b1c1a6dcb19b40c033b1da66d068cbf60d459c8ab6ec238b9701531 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10775 | 10664 bytes |
font_02_sfnt_off00011fe9.bin787a69d569192b3f25e6d6fd835ef1fe565f8df1d75819ea37c6473750079867 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11FE9 | 28316 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.