MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that directs users to a suspicious domain, likely to host a phishing page or download further malware. The document body, though obfuscated, appears to be a lure related to search queries.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/strik?utm_term=what+are+the+4+theories+of+motivation
- https://cdn.sqhk.co/febenapox/dvj0NkA/vesatupokegovi.pdf
- https://cdn.sqhk.co/remimidotomi/4ldgiIH/45593722897.pdf
- http://mukinokelek.mygamesonline.org/41871230191.pdf
- http://pemufosapakem.mypressonline.com/pixarefiwafuwus.pdf
- http://kedugobepuged.mywebcommunity.org/why_wont_my_bobbin_wind.pdf
- https://cdn.sqhk.co/rutunidosaw/ghdjaib/vepuvarawezizerojetarat.pdf
- http://dobikan.22web.org/dream_yuga_reserve_tank_capacity.pdf
- http://fusekimutoxi.sportsontheweb.net/jaundice_blood_test_report.pdf
- http://runojiwum.getenjoyment.net/zumirubujobuvikipi.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/698dfff1-a65d-463a-b9bd-b5fab930ffb8/goat_simulator_payday_free_download_android_apk.pdf
- http://gawexerexi.rf.gd/bezupewi.pdf
- https://uploads.strikinglycdn.com/files/48770037-db5d-49f7-8091-97c50cf2aab9/how_to_sync_sandisk_sansa_mp3_player.pdf
- https://uploads.strikinglycdn.com/files/071d7d29-2d0f-443a-b8c5-60cd5a662064/how_many_carbs_are_in_a_wendys_side_salad.pdf
- https://uploads.strikinglycdn.com/files/78fac57d-6428-4ce5-a462-67e930838cf6/riwafajaxigojow.pdf
- http://furubaja.epizy.com/7.5_western_unimount_snow_plow_weight.pdf
- https://uploads.strikinglycdn.com/files/0abc6809-ce91-40f1-bbac-fd2cc5260455/is_free_willy_2_on_disney_plus.pdf
- https://uploads.strikinglycdn.com/files/f000bf8d-a110-435f-b515-66fc67edaa90/besomeja.pdf
- http://rofatumetewebil.epizy.com/36947968964.pdf
- https://uploads.strikinglycdn.com/files/7cb232cb-2910-4f77-b4d0-ca37d4e687c4/crappie_fishing_lures_for_sale.pdf
- https://uploads.strikinglycdn.com/files/21be6ce3-efdd-4cf4-b3d0-655d3cd2fb25/42627974398.pdf
- http://verirajoxa.epizy.com/8317786184.pdf
- https://uploads.strikinglycdn.com/files/c181f537-c283-48b2-b3cd-3b8e739d9ad9/waring_food_dehydrator_instructions.pdf
- https://uploads.strikinglycdn.com/files/ea0eff66-840d-4547-86bd-cf7c2b6d845f/linux_unix_commands_cheat_sheet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000101c0.bin2b798105de35a60a1e5e8201274ab1bb417e04d04233234e36495cb4ddf068c5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x101C0 | 5136 bytes |
font_01_sfnt_off00011325.bin2f501769558b3dd2d5fb3efbe98cbf2eaea93f5a7a8e2bdd474720ddec0dbff2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11325 | 10016 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.