MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The embedded URL points to a suspicious domain, likely serving as a lure for phishing or malware distribution. No scripts were extracted, but the presence of an external URI suggests an attempt to redirect the user to a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9989
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://seumenha.ru/123?utm_term=vayne+top+guide+s9
- https://cdn-cms.f-static.net/uploads/4449614/normal_603a44b0f3190.pdf
- https://kasugokadudibuk.weebly.com/uploads/1/3/4/7/134740653/satokasevuf-sewax-fofofegas.pdf
- https://xoretesani.weebly.com/uploads/1/3/4/3/134315313/gesiriguxalarod.pdf
- https://cdn-cms.f-static.net/uploads/4501045/normal_60260569ae880.pdf
- https://gonupedifi.weebly.com/uploads/1/3/4/5/134524362/nezanadafal.pdf
- https://cdn-cms.f-static.net/uploads/4492246/normal_60676770cd06f.pdf
- https://cdn-cms.f-static.net/uploads/4392474/normal_606e7854d148d.pdf
- https://vififeroxesazu.weebly.com/uploads/1/3/4/7/134737415/1343772.pdf
- https://fijisakotapabe.weebly.com/uploads/1/3/4/0/134013267/5974794.pdf
- https://mubelumovetofap.weebly.com/uploads/1/3/1/8/131856402/3989df.pdf
- https://cdn-cms.f-static.net/uploads/4368956/normal_60482545108f4.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/b1036cee-907a-4497-a734-d4e69a35ca36/45919343474.pdf
- https://uploads.strikinglycdn.com/files/ad25b760-beea-42d0-9d08-6c94bdb1e330/12809463457.pdf
- https://uploads.strikinglycdn.com/files/86ef076a-2afe-4b99-9a68-a173d4b688b9/pezizigopusi.pdf
- https://uploads.strikinglycdn.com/files/4ea1d667-8302-4c45-b97a-a8baa5cef087/vimulimameva.pdf
- https://uploads.strikinglycdn.com/files/c927bcc4-0b83-42fb-884b-fde227eafc5b/samsung_scx-4623_printer_manual.pdf
- https://uploads.strikinglycdn.com/files/05a70332-4e82-4d77-8967-9387ffe5d397/degive.pdf
- https://uploads.strikinglycdn.com/files/ac6c8b6e-f4b6-4f75-931c-309b08bf0a44/bozumasenoxekelilize.pdf
- https://uploads.strikinglycdn.com/files/b3dbf240-8dd8-4956-b2ad-5d13540fe6b5/solel.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00029644.bin0ede0b99629174f3f6e6f6a60f2808bd667b07a5a31fb5c0c8b49c1a21784c47 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x29644 | 5104 bytes |
font_01_sfnt_off0002a7b1.bin246d6d632482fd47d210db2f3a19d3773e2ac3a5abe9dc8bd3570c28c8bb37fa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2A7B1 | 2928 bytes |
font_02_sfnt_off0002b3ff.bin777f3e71ba04b0f59706d8111353e47de7d4c85d3b864f5a8d6bd521dd58b762 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2B3FF | 15620 bytes |
font_03_sfnt_off0002e15b.bin9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2E15B | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.