MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'https://soxebez.ru/award?keyword=list+of+causative+verbs+in+english+pdf', which is likely a phishing or malware distribution lure. The document body, though heavily obfuscated, suggests it is attempting to masquerade as a search result for a PDF document.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/award?keyword=list+of+causative+verbs+in+english+pdf
- http://lnstagram-blue-ticks.com/polojonuditegaw7753.pdf
- http://chelobaka.space/8063889319rob1g.pdf
- https://cdn.sqhk.co/mikedeto/jdFEtuU/banco_bradesco_s._a._bbd_bcba.pdf
- https://cdn.sqhk.co/lajakukilo/jjhbzhf/mineral_water_good_for_your_skin.pdf
- http://porn77.design/99480907734l0ofu.pdf
- https://cdn.sqhk.co/nogorodizet/gfj926f/54632366494.pdf
- https://cdn.sqhk.co/zatejurix/bbhjicY/rotator_cuff_tear_symptoms_tingling.pdf
- https://cdn.sqhk.co/jofutagi/ha9qkjh/mokodugu.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/781ed611-b1d0-449b-93ca-22d6efad07b8/adobe_premiere_pro_cc_2017_serial_number_list.pdf
- https://uploads.strikinglycdn.com/files/9e87f8af-8ae3-424b-86a1-2daf0b832072/how_to_adjust_draw_weight_on_bear_apprentice_2.pdf
- https://uploads.strikinglycdn.com/files/214a9b4d-5c1e-4ef4-ba4e-d301b17f63a8/lenormand_cards_meaning_whip.pdf
- https://uploads.strikinglycdn.com/files/b594f2f8-f0c4-4041-b983-d0f5cdbb6203/costco_phonak_brio_3_price.pdf
- https://uploads.strikinglycdn.com/files/3be4c02c-d110-4546-a67d-7802c7f9b5a3/86213905418.pdf
- https://uploads.strikinglycdn.com/files/7bdfc016-6f36-4448-aee0-f78a2b475d81/862960546.pdf
- https://uploads.strikinglycdn.com/files/b59fb9a9-de51-4b03-ad47-0aaa328ce708/the_last_leaf_summary.pdf
- https://uploads.strikinglycdn.com/files/c13fce85-8cb1-4f69-8aee-a5aa0a782e23/burger_king_coupons_2021.pdf
- https://uploads.strikinglycdn.com/files/d52cd492-6709-4381-9589-6af0ba9248b5/globus_travel_reviews_ireland.pdf
- https://uploads.strikinglycdn.com/files/d5d18a16-5f4f-4711-ac08-5f5e81981765/lizusilizupotiwoluw.pdf
- https://uploads.strikinglycdn.com/files/dd26b825-5eb7-4a0f-ba07-9c1455768521/jolly_grammar_3_teachers_book.pdf
- https://uploads.strikinglycdn.com/files/6ac14079-1a9b-4111-b579-87e68967be7c/apc_back-ups_xs_1300va.pdf
- https://uploads.strikinglycdn.com/files/f0b4d2c8-49e6-4336-852c-d8efe511d39f/chrome_flash_plugin_enable.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f32d.bin57a285f8dbbe8659a577bf5737839a1cfe09b5578d54359cc178d2b90ccd1430 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF32D | 5560 bytes |
font_01_sfnt_off00010616.bin0dbb9eddd9c8659a3fb68fd5e7c0abac53de8ba163b4804914c531f28c84d3e3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10616 | 10932 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.