MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URI that directs the user to a suspicious domain, likely a phishing lure. ClamAV and ML classifiers also flagged this PDF as malicious, specifically identifying it as a phishing trojan. The presence of external URIs and the nature of the heuristics suggest an attempt to redirect the user to a malicious site for further exploitation.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/wb?keyword=what%20is%20first%20angle%20projection PDF link annotation
- http://thelandofbadideas.com/977007149292rie7.pdfIn PDF document text
- http://am-sound.ru/lixinezujisawelejutiss92k.pdfIn PDF document text
- https://gitinegu.weebly.com/uploads/1/3/4/6/134648864/c2e468b2026ace.pdfIn PDF document text
- https://zegoliro.weebly.com/uploads/1/3/2/3/132303320/dagukakawibo.pdfIn PDF document text
- https://jaluzirilunotu.weebly.com/uploads/1/3/2/6/132681851/vadiz-xopus.pdfIn PDF document text
- http://hyipinvest.site/785337322695mr9v.pdfIn PDF document text
- http://indohealth365.online/where_should_u_take_a_lost_saladozcpi.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4421039/normal_5ffe6ddf4bd53.pdfIn PDF document text
- http://kinokaiff.space/cell_wars_level_207rta9i.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4475389/normal_603244e9743fe.pdfIn PDF document text
- https://funogumoduwe.weebly.com/uploads/1/3/4/3/134309977/tosekamuxamatuw.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4379483/normal_6002d5becfd1d.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4459170/normal_5fcb9a82f1f60.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://s3.amazonaws.com/zuguvoxoki/wofewinunupiwepisidalaver.pdfIn PDF document text
- https://s3.amazonaws.com/pizivurapab/gidinulaluwidado.pdfIn PDF document text
- http://zexitan.rf.gd/zulozavodadorulejuv.pdfIn PDF document text
- https://s3.amazonaws.com/dojivewobasuval/addons_builder_for_minecraft_pe_apk.pdfIn PDF document text
- http://lajefuvubesij.epizy.com/alternating_current_circuit_analysis.pdfIn PDF document text
- http://nadiripu.epizy.com/schedule_template_canva.pdfIn PDF document text
- https://s3.amazonaws.com/pilazi/welofibukutabin.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010828.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10828 | 5156 bytes |
SHA-256: f8569bac55b1b2e2aa489f2ff4547f4ebee5b6c7f99f095ee8d0b5aa26fb67da |
|||
font_01_sfnt_off000119ae.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x119AE | 11096 bytes |
SHA-256: 22039a4bf8d92a608840ccb4431b37af3f99517f998933c14a69d9fb7ae6c814 |
|||
font_02_sfnt_off00013f98.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13F98 | 16028 bytes |
SHA-256: 3e66ce8c90719045bf8f6c8d5f716325bbce29c89c8399c9e71e7e90b46a9b16 |
|||
font_03_sfnt_off000153e1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x153E1 | 4324 bytes |
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.