MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The embedded URL, 'https://leonvi.ru/strik?utm_term=harry+potter+and+the+prisoner+of+azkaban+book+quiz', is the primary indicator of compromise, likely serving as a lure for phishing or malware delivery. Although no scripts were extracted, the PDF structure and heuristics suggest it's designed to exploit user interaction via the embedded link.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/strik?utm_term=harry+potter+and+the+prisoner+of+azkaban+book+quiz PDF link annotation
- https://cdn-cms.f-static.net/uploads/4428083/normal_604ce5a25398a.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4371809/normal_602d9313a03e0.pdfIn PDF document text
- https://static.s123-cdn-static-d.com/uploads/4478687/normal_60aff64c3361b.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4452612/normal_605d52af04a06.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4368760/normal_605033b990e3c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4426279/normal_605e0ab9411ff.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4472488/normal_5fffcbced1365.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4454303/normal_5ffb2e26db36d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4365634/normal_600fdadf9bb88.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4378381/normal_604031835b2ba.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4387821/normal_6018c3d1cf828.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/e1a4c8c3-c8c7-4642-be00-d2c010148e7e/nc_drivers_license_office_greenville_nc.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ab0bd779-2559-4ab1-89bf-b8cbfd84ccfc/31820668451.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1d417000-9220-474a-bc8a-f5b0740922ae/what_is_end_stage_arthritis.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0f3d4a76-332d-4aca-9e4c-359b997c0a9b/cell_organelles_and_features_worksheet_answers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6e61e947-a451-4d3d-b63c-09033cafaca3/viking_refrigerator_installation_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6a1385e7-e70e-4a12-a064-2a9240cb83ed/eye_of_the_beholder_dd_game.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b0548103-f577-491a-9567-ead80cb59382/surface_area_of_cylinders_cones_and_spheres_worksheet_answers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c046e85d-4c91-44c5-96fd-3a79c6ad88df/67908864800.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/95eaa085-5a2f-414f-b4d5-37fc8b6723c9/download_samsung_galaxy_s_iii_neo_gt-i9300i_firmware.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ea371773-ba44-422f-9952-a3dfeac903e7/how_do_i_use_the_wps_button_on_my_spectrum_router.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7de946c9-c581-4759-ab17-bf288206fd2e/casio_wk-110_midi_driver_mac.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/124f1fcd-26f8-4da1-b16a-59d44c83c306/22062206644.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/16d51808-8892-4f44-99f1-dcfe30da2c78/66572014819.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c7ce4b79-14eb-47c3-a89c-a5e7ed472328/microsoft_excel_file_to_converter.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ed0f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED0F | 5540 bytes |
SHA-256: b0bec2c333b8fcd85ed6d65a671831ad87ab030c18b26f5bf7f32c8446354bfd |
|||
font_01_sfnt_off0000ffe8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFFE8 | 11412 bytes |
SHA-256: 90078c8a179144166c49f8f43bb0fca2fc31259a2ed87ee176271032800b89d9 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.