MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, with a high risk score. It contains embedded URLs, one of which is associated with a phishing lure referencing 'Diablo 3 ps4 hacked items'. While no scripts were directly extracted, the presence of embedded URLs and the nature of the lure suggest a phishing or scam attempt, likely delivered as a spearphishing attachment.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://dfds.in/what_is_noise_in_the_knife_of_never_letting_goafqh2.pdf In PDF document text
- http://vesefotaso.iblogger.org/how_long_do_you_leave_splat_dye_in.pdfIn PDF document text
- https://cdn.sqhk.co/posukomokufi/heXeYgh/the_great_tournament_2_walkthrough.pdfIn PDF document text
- https://cdn.sqhk.co/gabogivoxavi/4ibxGhi/a_tag_knight_mod_apk_android_1.pdfIn PDF document text
- http://habirovradik.ru/hillsborough_nh_school_district_calendarw556i.pdfIn PDF document text
- http://sfhgfje5df.xyz/23383765572yz7sr.pdfIn PDF document text
- https://cdn.sqhk.co/fagaxirupunu/jbjgoAt/konapowetoginuralarexa.pdfIn PDF document text
- https://cdn.sqhk.co/dodalowogiv/mhahkie/jester_darkest_dungeon_guide.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://feedproxy.google.com/~r/wb/ENAH/~3/0IJhScypsXo/wb?keyword=diablo%203%20ps4%20hacked%20itemsPDF link annotation
- https://s3.amazonaws.com/tinivukedeta/hot_rolled_steel_sheet_specifications.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/84d9e2a7-b21e-4d94-8ffb-fb9044f9a50f/dedenesokewikamedad.pdfIn PDF document text
- https://s3.amazonaws.com/woxotopapozokev/let_the_king_of_my_heart_bethel_chords.pdfIn PDF document text
- https://s3.amazonaws.com/xefejevife/android_fragment_onattach_deprecated.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ac3f58a6-bf21-4fb6-9094-3e7dea8da513/how_to_reset_a_electrolux_washer.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a5b7aba1-5674-40c5-bcf4-5e810537c069/ge_true_temp_oven_control_panel_not_working.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1c2bec0f-ac35-4036-b6b9-2d0012bd76fc/sennheiser_rs-175_wireless_headphones_and_receiver.pdfIn PDF document text
- https://s3.amazonaws.com/vaxebisapesi/betternet_vpn_google_chrome.pdfIn PDF document text
- http://nijopupeboxisa.epizy.com/59548094134.pdfIn PDF document text
- http://lufubafuma.epizy.com/18236881845.pdfIn PDF document text
- https://s3.amazonaws.com/wewiro/grinds_my_gears_meme_template.pdfIn PDF document text
- https://s3.amazonaws.com/befafuni/22979683341.pdfIn PDF document text
- https://s3.amazonaws.com/midizaxopazeji/gofunupedekufi.pdfIn PDF document text
- https://s3.amazonaws.com/wajufifenoxuj/how_do_i_find_my_remote_access_code.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f02c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF02C | 2912 bytes |
SHA-256: b3177c8de935bf2e05ba58035bb430970af2c83108b60a2dfb12b0772094c699 |
|||
font_01_sfnt_off0000fa87.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA87 | 5672 bytes |
SHA-256: 577905d9c18f284484bfd975f99043b6c320497100e417718e31aca6b40b6897 |
|||
font_02_sfnt_off00010db1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10DB1 | 11324 bytes |
SHA-256: 2e277150361dee422e4364461bcc049fc3e90fd7dec43bff3246e31f9aa0c87a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.