MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains an embedded URL that mimics a search result for a common query, likely to trick the user into clicking it. ClamAV and ML classifiers flagged this PDF as malicious, specifically as a phishing trojan. The presence of an external URI and the overall detection suggest a phishing attempt designed to lead the user to a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/strik?utm_term=what+does+it+mean+when+my+oil+light+is+flashing
- http://tumibejum.iblogger.org/netflix_expired_meaning.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/e142eff8-24bf-43eb-acf3-70dc487dd371/calories_in_a_sonic_breakfast_burrito.pdf
- https://s3.amazonaws.com/vuzufexarevima/singapore_work_permit_visa_application_form.pdf
- https://uploads.strikinglycdn.com/files/20a6ef13-4589-4c78-8357-de954e5b780b/32716620970.pdf
- http://kokasog.epizy.com/66490595709.pdf
- https://s3.amazonaws.com/bezorito/the_indian_ocean_tsunami_of_2004_worksheet.pdf
- https://uploads.strikinglycdn.com/files/121eefa5-6e66-457a-9cc7-285cc1ecd443/59147230142.pdf
- https://uploads.strikinglycdn.com/files/b4a42d2d-10b4-4157-aadb-5f9906d182f8/black_and_decker_20_volt_drill_manual.pdf
- https://uploads.strikinglycdn.com/files/c1f78605-563b-42ee-8f32-9eee3b8f7a25/what_are_examples_of_professional_achievements.pdf
- https://uploads.strikinglycdn.com/files/67ca8b6d-d8cb-4156-a29f-e7781d7f8a8c/rurudowoluwopajivufuje.pdf
- http://luvenawow.epizy.com/82034677953.pdf
- http://luselobek.epizy.com/39941539536.pdf
- https://uploads.strikinglycdn.com/files/e9ef726e-559f-4a8a-a098-7b7b492f2aa6/togizipizubedipuxo.pdf
- https://s3.amazonaws.com/vukusa/vawuwiramiguburuwagas.pdf
- https://uploads.strikinglycdn.com/files/79f9ebaf-7786-42dc-bc29-b6d9adcc11d8/21228941000.pdf
- http://jelasojeb.rf.gd/zunaratilipolefenira.pdf
- https://uploads.strikinglycdn.com/files/233f0f1a-3bfe-4a09-9367-3879a70c3f39/zenusoviwalogakimavoje.pdf
- https://uploads.strikinglycdn.com/files/25664b94-ee8d-495a-be42-1d70afe21ccc/how_do_you_write_a_short_story_in_one_day.pdf
- https://uploads.strikinglycdn.com/files/0add8bae-b801-4345-85fc-73d312ef337d/vemevipoxujebi.pdf
- https://uploads.strikinglycdn.com/files/3f387116-6d47-4a96-bf8e-d7c6eba88ab4/excellent_gifts_for_mothers.pdf
- https://s3.amazonaws.com/tutasujal/mesugivuvoba.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e520.bin83d490944b8f8664bdb082a581ce620f262426f3114a9a0d682257cf7c594b2c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE520 | 5432 bytes |
font_01_sfnt_off0000f799.binf49125ffcbc2a8d0ddb9e75698bbe15d27708dcbffdfec7ab09c7d866f5a13ac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF799 | 10344 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.