MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains heuristics indicating an external URI and is flagged by a machine learning classifier and ClamAV as malicious. The embedded URL 'https://soxebez.ru/wix?keyword=april+fools+worksheets' is likely used to redirect the user to a phishing or malware distribution site. The document body, though heavily obfuscated, contains text related to 'April fools worksheets', suggesting a social engineering lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/wix?keyword=april+fools+worksheets
- https://cdn-cms.f-static.net/uploads/4479451/normal_602d8033185d3.pdf
- http://batmbatm.ru/saxajegixi3sao4.pdf
- https://cdn-cms.f-static.net/uploads/4373243/normal_6052d2a377ac5.pdf
- https://rijagadufe.weebly.com/uploads/1/3/1/6/131606992/mabiwoveva.pdf
- https://gitodaxip.weebly.com/uploads/1/3/5/9/135960033/5383338.pdf
- http://gerda-msk.ru/474764057113lhij.pdf
- https://gidipefodato.weebly.com/uploads/1/3/5/3/135348522/3073032.pdf
- https://cdn-cms.f-static.net/uploads/4382627/normal_6035a282338ad.pdf
- http://bathforlegs.xyz/spotlight_room_escape_level_1_afterlightitoxp.pdf
- https://static.s123-cdn-static.com/uploads/4482858/normal_5fcc1f3dbac2a.pdf
- http://cadenalia.com/49581667686il69d.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/fajeloninesitel/23994439959.pdf
- https://7211abc3-b26e-437e-abd8-8a8c7ebd4af5.filesusr.com/ugd/0683fb_8b78668cb1ec49fab711984bdba15dce.pdf?index=true
- https://ba3a7bb5-edd2-4228-b29c-cf272df6a868.filesusr.com/ugd/bd1c09_24d5f4c731a44d998e0cfef33dbd8906.pdf?index=true
- https://s3.amazonaws.com/jagux/best_romance_novels_for_12_year_olds.pdf
- http://mebexadesojixip.rf.gd/56404973298.pdf
- http://navibizo.rf.gd/fdic_call_report_information.pdf
- https://s3.amazonaws.com/nufidibodudulad/full_size_bed_sheet_dimensions_in_inches.pdf
- https://s3.amazonaws.com/vavale/lepovuwilurirezata.pdf
- http://tuzawuza.epizy.com/pepugigojibimajafo.pdf
- https://s3.amazonaws.com/wozowuledij/25968218583.pdf
- https://5457524e-bace-410a-9ce7-c8d8bc0eedea.filesusr.com/ugd/f0ffd0_700a784c2eb04cf2bf8d0cd4a2eb1190.pdf?index=true
- https://bee08bb6-d8c1-4cc5-89f0-d6ac88a4f64a.filesusr.com/ugd/8b8a1f_84255a8618204b9b8bbffba649bdce77.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e4d5.bin3784aec7be16fc78512048f90e391cee7d5dadd8d2af15730f70def6123255da |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE4D5 | 4924 bytes |
font_01_sfnt_off0000f5ab.bin16f6e3dadda7e3682e49b051af6636893bdc355cc171e91c3f1a10b08a4b07d4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF5AB | 11020 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.