MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. The document body, though heavily obfuscated, contains references to movie downloads and a URL that likely serves as a lure for malicious content. The presence of embedded URLs and the overall structure suggest an attempt to trick the user into downloading a payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://medvor.ru/pbw?utm_term=the+mummy+3+2008+hindi+dubbed+movie+download+480p
- https://static.s123-cdn-static.com/uploads/4496391/normal_5fe38b7443c07.pdf
- https://cdn-cms.f-static.net/uploads/4413465/normal_6054fba9936d1.pdf
- https://static.s123-cdn-static.com/uploads/4490122/normal_5fee01c3990f0.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_60365f9ecbd9c.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/ca30bb51-29ef-447e-9263-dfc3ef6d90ac/50750154463.pdf
- http://tosuvop.pbworks.com/f/loxojodovejulolobuwemod.pdf
- https://uploads.strikinglycdn.com/files/9dd844c9-c6bc-486f-a60c-ce19babe8735/tojuxofelemuxamadir.pdf
- https://uploads.strikinglycdn.com/files/45a97dca-6846-44f2-bbb8-679da989bb96/pujof.pdf
- https://uploads.strikinglycdn.com/files/66c8e2a4-d138-47e1-878d-f10ee4507085/how_to_begin_healing_from_childhood_trauma.pdf
- https://uploads.strikinglycdn.com/files/c838e41b-82b6-4cc2-b6f8-c63841cd2000/what_is_the_best_cordless_miter_saw.pdf
- https://uploads.strikinglycdn.com/files/72458ef8-c775-4664-8dcf-e100a8ed0812/selefinerejarepekim.pdf
- https://uploads.strikinglycdn.com/files/08e68189-2bbc-40a0-bce5-eac2eb20b002/hoover_dual_power_max_carpet_cleaner_manual.pdf
- https://uploads.strikinglycdn.com/files/a4c6b102-b2b4-4dd4-a658-4581751948cb/32346055773.pdf
- https://uploads.strikinglycdn.com/files/2d82b4c5-2df8-443e-81ac-f7be475309cc/kb_sock_loom_tutorial.pdf
- http://xugilip.pbworks.com/f/97144901705.pdf
- https://uploads.strikinglycdn.com/files/65280002-bf12-4a90-a350-bde1c2d01d95/55110923356.pdf
- https://uploads.strikinglycdn.com/files/e8cacf6d-db63-485a-93ea-28273725f88c/42853999634.pdf
- http://pefagisunel.pbworks.com/f/miner_premium_mod_apk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d4ee.bine71882d2e7a5a665c1273848dc02cdeb49d2939d96e55ee1045c57645b9d6085 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD4EE | 5988 bytes |
font_01_sfnt_off0000e94b.bin7a74f3931a7a72643483fc998a7634c4d1fc690ae575f393b7aa0b7ff4ca69f0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE94B | 11272 bytes |
font_02_sfnt_off00010f82.bina95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10F82 | 16204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.