MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF was flagged by multiple heuristics as malicious, including a high-severity rule indicating an image lure linking to an SEO redirector for phishing. The ML classifier also assigned a high probability of maliciousness. The primary IOC is the external URI which leads to a suspected phishing domain.
Machine Learning
- Nyx PDF Classifier malicious score 0.9604
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xajibur.ru/strik?utm_term=d%2526d+5e+dungeon+master+screen PDF link annotation
- https://cdn-cms.f-static.net/uploads/4496824/normal_5fd789042e0e7.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4485809/normal_6066f15e2f757.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://fedorahosted.org/lohitIn PDF document text
- http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
- http://smc.org.inhttp://smc.org.inIn PDF document text
- http://www.indictrans.orgIn PDF document text
- http://www.opentle.orgIn PDF document text
- https://s3.amazonaws.com/jixeremipet/rs_dagannoth_kings_guide.pdfIn PDF document text
- https://s3.amazonaws.com/matogapibelifiv/nunokoluju.pdfIn PDF document text
- https://45dcde1a-aed5-4138-b95e-a0f768a283bf.filesusr.com/ugd/89441e_92e038174cba4ba99526e323e1fbbc7b.pdf?index=trueIn PDF document text
- https://e437b920-fa79-41d5-b67c-0ca059f4e77a.filesusr.com/ugd/d97c10_7ca8b8a194e64fb4b6f4aa63ce430d18.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/seriposuj/73604719251.pdfIn PDF document text
- https://s3.amazonaws.com/rivazixexuguri/ziwazunosunuwam.pdfIn PDF document text
- https://s3.amazonaws.com/jenagubadopi/kilulifumomokape.pdfIn PDF document text
- https://50037ee0-0691-4a53-bdc2-b2f8f795cfa6.filesusr.com/ugd/b41a9a_54ff4f79f4fe46faae425fc9100052aa.pdf?index=trueIn PDF document text
- https://332892e0-6a2b-40ad-946e-e7c92c61c867.filesusr.com/ugd/3e5d97_af0b0178563d44a583d57fc483db137f.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/2ec78185-6e67-4975-8377-7df1e6fee7d1/24414253571.pdfIn PDF document text
- https://s3.amazonaws.com/jasadavebaga/narasimha_kavacham_with_meaning.pdfIn PDF document text
- https://s3.amazonaws.com/voxulija/dutejebobafabenotokugu.pdfIn PDF document text
- https://99516632-72ce-40f3-a9a1-a01c91361c65.filesusr.com/ugd/e42c35_f6dcb7cb13314d0c871a0258577a99cb.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/xufaxoferugod/74740343121.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2f9d9dae-7840-4b36-8113-a9fb00d0d012/86977245257.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
- http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
- https://gitlab.com/smc/meera/blob/master/COPYINGIn PDF document text
- http://www.gnu.org/licenses/lgpl.htmlRegularDanhHongIn PDF document text
- http://www.geocities.com/dnhhngIn PDF document text
- http://sinhala.sourceforge.net/In PDF document text
- http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITSIn PDF document text
- http://www.gnu.org/licenses/gpl-2.0.htmlIn PDF document text
- http://www.gnu.org/licenses/gpl.htmlIn PDF document text
- http://scripts.sil.orgIn PDF document text
Extracted artifacts 17
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_016_off0002097d.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x2097D | 19380 bytes |
SHA-256: 0848011c5bc734ee643db138d530f95bec50730ff15d4ad7ce2dc2994fec1047 |
|||
font_00_sfnt_off00011bae.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11BAE | 7916 bytes |
SHA-256: 2e595141cfc5a730015d867094056734cd151f5b215480bba884d522f17c5808 |
|||
font_01_sfnt_off0001300e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1300E | 6484 bytes |
SHA-256: 1e87b7a3c04023d83bb783ac0da7f6e3ab9d38522fd237c691ec8c5711216dd6 |
|||
font_02_sfnt_off00014672.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14672 | 4156 bytes |
SHA-256: 4137e011fb50e940388b7a91a31e36f70741d8ce55ef6fbc7fb0314564e06879 |
|||
font_03_sfnt_off0001549e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1549E | 2656 bytes |
SHA-256: ff8289fcab20b7b81f5dc7c47458689637225d7099c48932a46d6898d6123f6c |
|||
font_04_sfnt_off00015fa3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15FA3 | 4140 bytes |
SHA-256: 2a2f73c0ee504ae8509221dab9a50e72e6c400a18e3952d3eee660ba18a0c3b1 |
|||
font_05_sfnt_off00016cc0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16CC0 | 3048 bytes |
SHA-256: b5c6b6e0c9ada0bf1c6b02372d38a6194b0fc304f51b15768a03b7bd417def48 |
|||
font_06_sfnt_off000178c9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x178C9 | 4544 bytes |
SHA-256: ff18c81e36cb9b15efdbce47b580caf324ee17e344593362339bc7644b00bcc1 |
|||
font_07_sfnt_off000186cf.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x186CF | 2328 bytes |
SHA-256: 18b250f24057ce91e4a59b25c1eec79fa8b4d7e2cb9f6c0de02c7e032a072fd4 |
|||
font_08_sfnt_off00019187.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19187 | 2604 bytes |
SHA-256: 5fd53e2058c4f5d98b70161d670f1e42036942552fef68ac845a5e47e2d7f715 |
|||
font_09_sfnt_off00019cad.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19CAD | 2108 bytes |
SHA-256: 5fc9e2cd4e7ad04544edda2023dd698132b65daf167a61e09de9fd8de66d8b52 |
|||
font_10_sfnt_off0001a64c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A64C | 3840 bytes |
SHA-256: 5b8e8035f8940535bfb5f3d78de7d5c45dbc51c905faa5d9788b8fc152e96872 |
|||
font_11_sfnt_off0001b465.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1B465 | 4336 bytes |
SHA-256: 87016e8933cc862d1d188edfbee698abcff8178ed3d6b510b61737ee02f60284 |
|||
font_12_sfnt_off0001c205.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1C205 | 6148 bytes |
SHA-256: 488ffee5e9c33bcc1f3f00aec749f35977d0cdd209ffadaee35194d66ecc177d |
|||
font_13_sfnt_off0001d1ef.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D1EF | 19028 bytes |
SHA-256: 33178f4e210377448a5e2f3c2369abfcfce26e77fc3fb355a284b4eb4929e6d1 |
|||
font_15_sfnt_off00022aed.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x22AED | 3612 bytes |
SHA-256: a3092163937b5c2949d1986ae69da3692f5096c98e1e1b86342fcf3090b92528 |
|||
font_16_sfnt_off0002390b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2390B | 4216 bytes |
SHA-256: 5cc8f364962355ae475115db944fd7a4d20f38d86c7f7c448382747ab212ad85 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.