MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URI pointing to 'https://zajinet.ru/strik?utm_term=is+513+thickness+tolerance', which is likely a phishing or malware distribution site. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, a tool sometimes used to create malicious PDFs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9956
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=is+513+thickness+tolerance
- https://cdn.sqhk.co/posiraki/oaicVgi/97069018142.pdf
- http://summ-green.fun/oracle_database_11g_administration_workshop_10zfde.pdf
- http://gufutaca3.xyz/75471108635193dh.pdf
- http://mabay.fun/drumsticks_on_the_grill_indirect_heat8puet.pdf
- https://cdn.sqhk.co/wadupaxi/hi0xgjB/nfs_heat_studio_pc.pdf
- https://cdn.sqhk.co/budajawisore/cdihvib/no_crop_story_instagram_apk.pdf
- https://cdn.sqhk.co/ratijojitud/ifCEcMS/79396368689.pdf
- https://cdn.sqhk.co/joziroluxu/AR44Jgi/decorate_my_dream_home.pdf
- http://hushseo.online/barfi_kannada_full_movie_freeg4g2k.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://0fdd9f25-8366-4660-9463-376fd915ad39.filesusr.com/ugd/c16cf9_65080c874a094c269d3327f81d2d5df3.pdf?index=true
- https://1c985592-4fe2-425a-b8d2-7dc24782370c.filesusr.com/ugd/a13bc2_8daccde9fbdd4986b69791b3e0a9b7d3.pdf?index=true
- https://s3.amazonaws.com/lomuper/51522540144.pdf
- https://uploads.strikinglycdn.com/files/6c2520f6-90ad-49ae-9694-44ee9f3d4148/hp_officejet_4500_printer_error_codes.pdf
- https://923a8ca3-316b-4844-b38f-9bc955ad4852.filesusr.com/ugd/312e0e_88eecf7fd6674c62b5ddebcd1dcbf0d1.pdf?index=true
- https://uploads.strikinglycdn.com/files/c01a709a-c755-445b-a959-bfdb3a5aa253/soundpeats_truecapsule_wireless_earbuds_black_review.pdf
- https://uploads.strikinglycdn.com/files/75621711-c3ad-4aad-8a04-e3479fae28cc/night_owl_security_camera_app_for_computer.pdf
- https://82e7f058-9c2a-4352-8e65-a162d98cde11.filesusr.com/ugd/ba3c76_49aaf7116f8741aa85ac43e35f6dcdda.pdf?index=true
- https://c3373aeb-ed74-4f2d-b631-fa679e0a3f6f.filesusr.com/ugd/cbe7f7_0084819992c24c1098a4a7d36c753551.pdf?index=true
- https://s3.amazonaws.com/muxegeza/dojemisejuran.pdf
- https://6b5d12f1-3bbc-48af-9ddb-5430d2fe15e7.filesusr.com/ugd/3bf302_5b43ef17e4a1461fa6dc8f34bcbafe65.pdf?index=true
- https://s3.amazonaws.com/zibenoroduzuw/syllabus_of_class_12_physics_pseb_2020-21.pdf
- https://s3.amazonaws.com/dudigonifu/canadian_multi_engine_flight_test_guide.pdf
- https://d8d078ea-10ec-4787-8e21-ef6e32b87a24.filesusr.com/ugd/8f6098_2d07c9c4bd89447c97cec9706114cb4c.pdf?index=true
- https://85d2c5a2-fc31-4f76-86b4-4ebe2abe2bf4.filesusr.com/ugd/a8cc01_4ad3c7a77f8642d9af1e23b189180bb0.pdf?index=true
- https://3f735f5a-cd1c-4288-bd93-adeff6e084d9.filesusr.com/ugd/bcc0e4_004367e5245e4256be6770602ff418b5.pdf?index=true
- https://s3.amazonaws.com/sinamozagemoger/instagram_blockierung_aufheben_android.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dc84.bin4678caf21fc0dbeaf6f651a0c2abaceccdc2a7115025ca37fb4dff5a8fb5675d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDC84 | 5228 bytes |
font_01_sfnt_off0000ee4f.bineef382c911d113aa8aba469c7874f1c79727682e7c35f06102c190f23c99083f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEE4F | 11016 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.