MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. It contains an embedded URI pointing to 'https://kuzutuzo.ru/strik?utm_term=best+core+trx+exercises', which is likely the primary lure. Although no scripts were explicitly extracted, the PDF structure and the presence of external URIs suggest an attempt to redirect the user to a malicious site, characteristic of phishing or malware delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=best+core+trx+exercises
- https://xevibobi.weebly.com/uploads/1/3/4/6/134683071/46666.pdf
- https://cdn-cms.f-static.net/uploads/4378623/normal_5fe9ab6bccb3e.pdf
- http://vuxuvex.iblogger.org/choji_akimichi_butterfly_form.pdf
- https://cdn-cms.f-static.net/uploads/4383467/normal_605dc857d65f9.pdf
- https://likimipezerejo.weebly.com/uploads/1/3/2/6/132682052/wokavuwe.pdf
- https://xaxibilezulaf.weebly.com/uploads/1/3/4/0/134096047/jazibudemiv_jewafavan.pdf
- https://cdn-cms.f-static.net/uploads/4493221/normal_6017392426213.pdf
- http://wonitudigugejut.iblogger.org/mupeduwazexaz.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/fevobelijogal/54621637238.pdf
- https://uploads.strikinglycdn.com/files/4be3c717-e9f7-41ab-9110-852946e5677d/how_to_lock_hidden_photos_on_iphone_8.pdf
- http://revifobatuge.rf.gd/al_nahar_drama_tv_guide.pdf
- https://s3.amazonaws.com/vudivuzakal/how_do_i_factory_reset_my_apple_airport_extreme.pdf
- http://xotesevuves.epizy.com/jijotekagarabazetos.pdf
- https://s3.amazonaws.com/nuvukivaxiren/75983666658.pdf
- http://jutepopoladajol.epizy.com/bluestacks_3._0_free.pdf
- http://dozesika.epizy.com/96458771133.pdf
- https://uploads.strikinglycdn.com/files/b0ded71e-a569-449d-901a-0ad4bcd7c057/irregular_verbs_list_in_english.pdf
- http://favekagopu.epizy.com/7407580579.pdf
- https://uploads.strikinglycdn.com/files/d811d849-a472-4885-a95b-4426d394385c/who_is_lucifer_as_per_bible.pdf
- https://uploads.strikinglycdn.com/files/e7b70931-9b01-4332-b62d-02748ca254d8/66896576349.pdf
- https://uploads.strikinglycdn.com/files/5edea5de-b718-450d-88f5-ed73857a2056/how_to_profit_in_forex.pdf
- http://nodonukebonona.epizy.com/focusing_on_ielts_academic_practice_tests_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010338.bin516dc85cb2262c0bc44666406d34944190b5074936d61f1883038993eb1027bc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10338 | 4668 bytes |
font_01_sfnt_off00011332.bin4ef5712480a523a45f1c1675dc482e5ac367dd80f094758494259379d02bb898 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11332 | 10636 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.