MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF containing an embedded URL that leads to a suspicious domain, likely intended for phishing or malware distribution. ClamAV and ML classifiers flagged this PDF as malicious, specifically as a phishing trojan. The presence of an external URI and the overall detection indicate a malicious intent to trick users into accessing harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/award?keyword=e%25C4%259Fitim+bir+sen+aday+%25C3%25B6%25C4%259Fretmen+kitab%25C4%25B1+5.+bask%25C4%25B1+pdf
- http://lifeeuro.info/paid_time_off_after_terminationi7mgb.pdf
- https://cdn.sqhk.co/razulati/cshblJ4/stick_war_2_order_empire_download_for_android.pdf
- https://cdn.sqhk.co/motuxeneb/rK1igjW/at_t_business_account_customer_service.pdf
- https://cdn.sqhk.co/miseseren/gjficha/3_webcube_dashboard.pdf
- https://cdn.sqhk.co/bozutebux/jhhifku/supertuxkart_multiplayer_split_screen.pdf
- http://particulier-societegenerale.xyz/powerasezovaxajujuznynu.pdf
- http://jexafagod.22web.org/4pic_one_word_level_2112.pdf
- http://topukovatawosu.sportsontheweb.net/top_down_bottom_up_listening.pdf
- https://cdn.sqhk.co/kuxixixixi/ic52zN2/visual_basic_programming_language_software_free.pdf
- http://zopaxonurur.iblogger.org/vijevif.pdf
- https://cdn.sqhk.co/wudawagirus/uRXgfhb/69553016010.pdf
- https://cdn.sqhk.co/famagafe/jhjfmTO/3278065265.pdf
- http://zarabotok.space/97351856103aqb75.pdf
- https://cdn.sqhk.co/vigamodijek/gjfq9ja/42481706108.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://makowadoka.epizy.com/sibonifuvikotu.pdf
- http://japinoxizidunub.myartsonline.com/66460846612.pdf
- http://lekeribujavopip.rf.gd/36537318823.pdf
- http://luwutijawalokug.rf.gd/60785229952.pdf
- http://jifupupuf.epizy.com/89401845708.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fed4.bindf6b89fb04f913360a4db294aff2f6f62639e5f3a05d76033c1c423cddf4e6da |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFED4 | 5972 bytes |
font_01_sfnt_off000112ef.binad9f5d3805005ef45ac572e6b5829a628e3262885ef1bb39ebc16ebec94f7f1e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x112EF | 11952 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.