MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing attempt. It contains an embedded URL that directs users to a suspicious domain, likely to host further malicious content or phishing pages. The document body, though heavily obfuscated, contains references to academic materials, suggesting a lure to entice users to click the malicious link.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/123?utm_term=uitm+past+year+answer+scheme
- http://potawuzaj.medianewsonline.com/43796988516.pdf
- https://static.s123-cdn-static.com/uploads/4413866/normal_5ffd706d12b81.pdf
- http://sunazeremitiwu.mypressonline.com/vovexegomip.pdf
- https://cdn-cms.f-static.net/uploads/4423189/normal_6055bac199b3c.pdf
- http://xufededubumavif.scienceontheweb.net/25414754410.pdf
- http://fontawesome.iohttp://fontawesome.io/license/
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/kudufigunabi/medical_surgical_nursing_gnm_2nd_year_in_hindi.pdf
- https://uploads.strikinglycdn.com/files/dfc41c45-3ac3-447f-88cb-547a999b4eca/38576092665.pdf
- https://uploads.strikinglycdn.com/files/f62b70d6-ac14-4d43-8a8b-fe90c58525f8/wisdom_for_mothers_book.pdf
- https://uploads.strikinglycdn.com/files/f4117c42-b107-4b59-946d-fa9f97193bdd/2001_kawasaki_prairie_400_4x4_rear_differential.pdf
- https://s3.amazonaws.com/ravuxudibure/dugunukuka.pdf
- https://s3.amazonaws.com/dalava/49325155085.pdf
- https://s3.amazonaws.com/wupiwupiwot/formatting_sql_code_online.pdf
- https://uploads.strikinglycdn.com/files/2c76ebb1-8c2a-4586-acc0-d5a794aefe78/how_to_pair_bluetooth_remote.pdf
- https://uploads.strikinglycdn.com/files/91c15976-7bba-4460-92f4-3f99ebe97850/magic_bullet_blender_large_cup.pdf
- http://vakizonozajaxe.onlinewebshop.net/achondroplasia_growth_chart.pdf
- https://s3.amazonaws.com/mulerux/98717205120.pdf
- https://s3.amazonaws.com/donukadizolin/3rd_grade_math_spiral_review_worksheets.pdf
- https://s3.amazonaws.com/zetubakuz/51923950870.pdf
- https://s3.amazonaws.com/jipowumat/copenhagen_card_city_guide_app.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ccf6.bincc0f98ba57fe256b33a2316005ffaa98fbd99cb032fb2885427ea1236117e1c5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCCF6 | 2080 bytes |
font_01_sfnt_off0000d685.bin7a20d9558f89c18fbd4152826a393300c2f2cafe0a27881a0bc2ff7ca6b55166 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD685 | 5324 bytes |
font_02_sfnt_off0000e88c.bin809bce8f35ed37f2177bf650093c00fac0b97c9d027632e0a893a95fa0fdc906 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE88C | 10316 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.