MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains multiple embedded URLs, one of which is presented as a lure for movie songs. The ClamAV detection and ML classifier strongly indicate maliciousness, likely a phishing or trojan delivery attempt. The presence of numerous URLs suggests a campaign to distribute further malicious content, potentially leading to a second-stage payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://drafthe.ru/uplcv?utm_term=chameli+movie+songs+free
- https://amirep.com/wp-content/plugins/super-forms/uploads/php/files/8d096a8a52bec96b34899b2c898f9280/16806615910.pdf
- https://gfow.om/wp-content/plugins/super-forms/uploads/php/files/5g5thfl8tisjsp7b70ktuaf86q/3011953738.pdf
- http://www.northeastmarquees.com/wp-content/plugins/super-forms/uploads/php/files/b812828a08f86f42ac914b5a3cb3a32d/punevimigiki.pdf
- https://www.mixedclass.com.au/wp-content/plugins/super-forms/uploads/php/files/uluddiehdpabvb9d57ml14u27d/59476064347.pdf
- http://3duct.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607eb8ba9575e---20252056065.pdf
- http://www.sunarozlem.com.tr/wp-content/plugins/super-forms/uploads/php/files/3u1pilsejua9g4d854nde7ac01/46325442098.pdf
- https://heritagelogs.com/wp-content/plugins/super-forms/uploads/php/files/52r84btbb2280uu1j7634o5gtn/59924013307.pdf
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/0a1636c230ff156d8d1595975e4d6998/puzurivivelibelutorivo.pdf
- https://www.andeanskyline.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609230508d49b---daduzabetituvuwaf.pdf
- http://thehawthornnyc.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078ed9adf59b---8172882742.pdf
- https://abril.pe/wp-content/plugins/super-forms/uploads/php/files/1biupatb308oseli5jg2k1rk64/worekabakematijowe.pdf
- https://www.clubmanizales.com.co/wp-content/plugins/formcraft/file-upload/server/content/files/1607603bca8ca8---87262596147.pdf
- https://divorcioconsensual.com.br/wp-content/plugins/super-forms/uploads/php/files/22e96e426cc31e21723e93398b27c78a/nitiradafifowe.pdf
- http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/16082a793d3895---sesovomariwuben.pdf
- http://penoplex24.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1607c9c1a6a20a---87194113630.pdf
- http://www.theagentpipeline.com/wp-content/plugins/formcraft/file-upload/server/content/files/16081648a3ace2---lodiputevafajonukugar.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dd66.bin8124b949417ee3dbf607fce4b63ca3fc3ce2b0e81a693c0f90077ea343d6532b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDD66 | 5148 bytes |
font_01_sfnt_off0000eebf.bin5c1cfbdc045b61d67a4946807fade1a3d799dfcffa24d5745ae1604d08c8e4c8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEEBF | 10872 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.