MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document that contains an embedded URL leading to a suspicious domain. The ML classifier and ClamAV detection strongly indicate maliciousness. The document body, though heavily obfuscated, appears to be related to health information, likely serving as a lure to the malicious URL.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/strik?utm_term=dosis+de+aceite+de+or%25C3%25A9gano+para+candidiasis
- https://static.s123-cdn-static.com/uploads/4495039/normal_5fe3e55496417.pdf
- https://cdn-cms.f-static.net/uploads/4490720/normal_6054be9387de0.pdf
- https://cdn-cms.f-static.net/uploads/4419826/normal_600feda672bba.pdf
- https://cdn-cms.f-static.net/uploads/4375886/normal_601f1d926c9b6.pdf
- https://cdn-cms.f-static.net/uploads/4373983/normal_601af32b70e2b.pdf
- https://cdn-cms.f-static.net/uploads/4405687/normal_603462f8ecb1b.pdf
- https://static.s123-cdn-static.com/uploads/4389820/normal_5ff17904a1b6e.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/927218e7-38e8-4a4c-8f05-5583f4c17207/jotupemuxomowonib.pdf
- https://uploads.strikinglycdn.com/files/0f3c076a-24b0-42b8-a995-1d9562f13510/how_did_art_change_during_renaissance.pdf
- https://uploads.strikinglycdn.com/files/4188f9a2-3231-4b4b-b5a5-2e4969374084/80332089920.pdf
- https://uploads.strikinglycdn.com/files/b433636e-47b4-409c-a3f5-d490af62da24/54307387599.pdf
- https://uploads.strikinglycdn.com/files/c33104a2-45c4-42a4-abe1-719dd7c254e6/elementary_linear_algebra_with_applications_9th_edition_by_kolman_and_hill.pdf
- https://uploads.strikinglycdn.com/files/2d62206e-7e3b-46bd-86e1-f60bcb4f852b/39110547820.pdf
- https://uploads.strikinglycdn.com/files/6068295e-5d70-41d3-bd78-9e9c4e336aae/89824141338.pdf
- https://uploads.strikinglycdn.com/files/59d49e77-a5f3-4792-9da2-1cdcfc829097/nojidi.pdf
- https://uploads.strikinglycdn.com/files/ad35976b-bd9e-4606-bd0c-3a7a15f06527/99653286760.pdf
- https://uploads.strikinglycdn.com/files/dd63c3cc-15ba-416b-ab10-3d1e63fb93ec/12102528771.pdf
- https://uploads.strikinglycdn.com/files/6d2e1492-b57a-449e-aabe-b627a321b2af/jizegonemezatosifet.pdf
- https://uploads.strikinglycdn.com/files/862ad67a-a6f0-4696-b8b3-2673b3f15126/61460781222.pdf
- https://uploads.strikinglycdn.com/files/51d3dd3c-123c-47cb-b2a1-85a0faa3b3d9/can_you_get_goat_simulator_on_ps4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001005f.bina21263d06bb8e659ec74b7935cb0eb701134af6b542efe7f3e3b51494394f577 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1005F | 5352 bytes |
font_01_sfnt_off00011264.bin78db2afaf1137151f9744df54bc466fe7425229b50208306cc0f1d902bcb0353 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11264 | 12140 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.