MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains embedded URLs pointing to external sites, one of which is `https://golowaki.ru/aws?utm_term=what+does+post+op+mean`, suggesting a phishing or credential harvesting attempt. The PDF structure and embedded content are consistent with a phishing lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://golowaki.ru/aws?utm_term=what+does+post+op+mean
- https://cdn-cms.f-static.net/uploads/4366309/normal_604f510bd271f.pdf
- https://cdn-cms.f-static.net/uploads/4458854/normal_600bdd2c60469.pdf
- https://cdn.sqhk.co/gixofusofago/dhdh1KU/liferay_6._2_interview_questions_and_answers.pdf
- http://groby-ritual.online/sorafibe7inri.pdf
- https://cdn.sqhk.co/tavaxikanabu/jcH8lhd/resident_evil_movie_chris_and_leon.pdf
- http://xesubixuj.iblogger.org/casio_g-_shock_5081_ga-_100cf_manual.pdf
- https://cdn.sqhk.co/zatugudaxaji/fhhG8ja/grist_mill_inn_hope_nj.pdf
- https://cdn.sqhk.co/xamozafi/9ZghhgH/human_centipede_part_2_movie.pdf
- https://static.s123-cdn-static.com/uploads/4385647/normal_5ff6860183d69.pdf
- https://cdn.sqhk.co/besudamuge/kjh0hgp/loruwidudirokitunoj.pdf
- https://cdn-cms.f-static.net/uploads/4501383/normal_602a12d19693b.pdf
- https://cdn.sqhk.co/jenojigise/gj40jic/falinevarid.pdf
- http://huseyincanx.com/jumefoa9gah.pdf
- http://figupatofewox.iblogger.org/all_souls_trilogy_espaol.pdf
- http://trend-sales.fun/rekitetawukesuxamettq4s.pdf
- http://sportita.fun/11432046041lhai8.pdf
- https://cdn.sqhk.co/tizesefetus/mghUNge/xozupafaz.pdf
- http://autobuff.xyz/acrobat_dc_freezes_windows_10q2wbf.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/viromibukoleliw/78801975724.pdf
- https://s3.amazonaws.com/zizene/mavebisarotuloxedetij.pdf
- http://nabafomubibatu.epizy.com/fafepofejixupuvumivegajo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ced7.bin968b66ff33efa70e4e33b8495821b4329a555c4952d93447d36bd618e2942b7d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCED7 | 5084 bytes |
font_01_sfnt_off0000e00d.bin343bff57f786be529759a29f32611c070d68e23ef2a6cc216c6b90912a822b86 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE00D | 11000 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.