MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that redirects to a suspicious domain, likely intended to trick the user into clicking it. The document body, though heavily obfuscated, appears to contain text related to the lure, suggesting a phishing attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9781
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/strik?utm_term=konosuba+light+novel+volume+15+vietsub
- https://roxodebovak.weebly.com/uploads/1/3/1/4/131454305/4082925.pdf
- https://risegexof.weebly.com/uploads/1/3/4/6/134661868/gavakiwebepakoxu.pdf
- https://cdn-cms.f-static.net/uploads/4426971/normal_5fda423b487c1.pdf
- https://xajimamu.weebly.com/uploads/1/3/5/3/135314586/runemonusove.pdf
- https://pixipemojawipe.weebly.com/uploads/1/3/4/4/134459682/ludogakov.pdf
- https://fekakekofum.weebly.com/uploads/1/3/4/6/134656499/985d1fc3d.pdf
- https://xajekedifa.weebly.com/uploads/1/3/4/4/134469171/4548258.pdf
- http://tesocoin.online/how_to_put_audio_files_into_garagebandsmrgg.pdf
- https://vopakumadojaga.weebly.com/uploads/1/3/4/3/134361244/85d7f0cba240f.pdf
- https://cdn-cms.f-static.net/uploads/4416512/normal_60226f779d27f.pdf
- https://panusefebile.weebly.com/uploads/1/3/5/3/135331690/ff768e.pdf
- http://sfhgfje5df.xyz/remote_working_information_technology_jobszpyyo.pdf
- http://eagleaff.com/20613793145bjiex.pdf
- http://beautytopshop.site/muveverenejipidanglrnt.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://1cdd1dcb-54a5-4750-95ad-c4cce9a68cd1.filesusr.com/ugd/1e32c2_9e102e2519d24a21a70544d928714d61.pdf?index=true
- https://144c9d4d-401b-437b-b89f-6a5816d7da47.filesusr.com/ugd/cd33f5_057e993b69d94933880196bc04df8592.pdf?index=true
- https://7f3356c1-ec1f-498a-9d41-5b36c14d87b7.filesusr.com/ugd/98d33d_ab7e126b8eab47baa668db42b71df393.pdf?index=true
- https://44bb6ee8-a0fe-4f72-890f-0f0a2fec05cf.filesusr.com/ugd/b65acf_24552ea7b5e54dc385737aa38835b31c.pdf?index=true
- https://34886cf3-15ed-44db-93e8-8979dc7c4cd7.filesusr.com/ugd/ea2c45_4b5ccbc893194e638040b20ce77c2ebb.pdf?index=true
- https://48bf584d-d56c-45cf-b4f3-c1c05dce5274.filesusr.com/ugd/3f4b99_1865143e79534f2680c727abf9b8355f.pdf?index=true
- https://e20d271a-53e3-41f9-9180-d6cd5f9fd148.filesusr.com/ugd/6cfc61_eab2c82c852746c4995d2b90b6abbcbf.pdf?index=true
- https://788ae96d-7a4f-4726-91a9-07bb742fb3e7.filesusr.com/ugd/97aff7_a5b96aa6a17246569cdc56809cb5ffd7.pdf?index=true
- https://8a89c5bc-485b-4808-980c-66c60e8d9908.filesusr.com/ugd/834936_16754f8e50e6471f967b2021102289bf.pdf?index=true
- https://0c2a7d7b-be9d-4ef2-a94c-09ca905cc17d.filesusr.com/ugd/7d21c0_794ba4d241794fa887f78b5142b2a631.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00016427.bin5ace02ca183208b26da6bdbd475fd7adf52a9c66fe13606a85d4cffdedf54c43 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16427 | 133816 bytes |
font_01_sfnt_off0002f385.bine11c5a58a36f2624ca65d41da1fbce2631ba686f774d9aa5accb75c9e225fb90 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2F385 | 5348 bytes |
font_02_sfnt_off000305a7.bin42bcd4c7eb3941890c6118d0aa3ee481c53e24d515f574d69a2639f11f0659bf |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x305A7 | 16484 bytes |
font_03_sfnt_off00033454.binc6733e3e220d2964eb936a5a62d9e094d3bdbb81ef9b6c34a738ed9280f319eb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x33454 | 16936 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.