MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains an embedded URL that leads to a domain associated with malicious activity, likely serving as a lure for users searching for educational content. No scripts were extracted, but the presence of the malicious URL and the phishing detection strongly suggest an attempt to redirect users to a harmful site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/strik?utm_term=holt+mcdougal+algebra+1+workbook+pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/f227732b-c77c-459d-87f2-3e90a896e337/18502168096.pdf
- https://s3.amazonaws.com/xeropizuwe/difomenozoletunajoxov.pdf
- https://uploads.strikinglycdn.com/files/78ecdf91-f1ff-4c2b-bfda-34d433fd0aff/73516890254.pdf
- https://uploads.strikinglycdn.com/files/a83a769e-f513-4287-9310-63e02ea8ea7d/bavivurediforevorefanuk.pdf
- https://uploads.strikinglycdn.com/files/4b45960d-3b55-4aff-93f8-90f1e278752f/everything_wrong_with_american_education.pdf
- https://s3.amazonaws.com/tajimipojimo/gonugapodubafabof.pdf
- https://s3.amazonaws.com/pewebopufupe/what_is_postage_for_overseas_letter.pdf
- https://uploads.strikinglycdn.com/files/36645f3b-f533-44ba-9417-90bd2314ac82/zepivogukax.pdf
- https://uploads.strikinglycdn.com/files/fc7110e2-ee50-4c42-94b4-970c3b5f4eef/ernest_norling_perspective_made_easy_espaol.pdf
- https://uploads.strikinglycdn.com/files/9130fb27-d57f-44d4-9350-6d502dbe94d0/tudoxokefuwupida.pdf
- https://s3.amazonaws.com/votawawo/zupuselitodu.pdf
- https://s3.amazonaws.com/fatisake/puffin_web_browser_pro_apk_mirror.pdf
- https://s3.amazonaws.com/mawesenasijoser/fesosekemaleb.pdf
- https://s3.amazonaws.com/zesixefe/devuboma.pdf
- https://s3.amazonaws.com/bitajemisajoz/joroj.pdf
- https://uploads.strikinglycdn.com/files/e2379184-62b9-4c8a-8aa4-2f31528b7a4b/asp.net_mvc_5_tutorial.pdf
- https://uploads.strikinglycdn.com/files/f006cb41-4599-4dfa-824c-051e9c674354/43928629462.pdf
- https://uploads.strikinglycdn.com/files/02a88639-1bad-4d52-be1a-d8cb13d97553/ultima_5_digital_tens_unit_how_to_use.pdf
- https://uploads.strikinglycdn.com/files/6a941fdc-ce37-4085-9933-d3df9c478f63/taco_bell_chicken_quesarito_nutrition_facts.pdf
- https://uploads.strikinglycdn.com/files/0bc6522a-1136-4bf3-b322-eeb0a7ae8e12/who_are_the_male_greek_gods.pdf
- https://uploads.strikinglycdn.com/files/100a0c63-e975-4201-a756-1395cf247e1c/most_popular_cognitive_biases.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ccbb.bin437f2995ebbedf60638013b5a8d5b17e8132a98c97dd1d3fc1ae865a767f2b2d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCCBB | 5604 bytes |
font_01_sfnt_off0000dfc9.bin27c5b853237a8d60f2edf0fc17055df550006542cc7a44164272405f93b79f97 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDFC9 | 10424 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.