MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file was detected as malicious by ML classifiers and ClamAV, indicating a high probability of malicious intent. The document body, though truncated, suggests a lure related to a game download, and numerous external URLs are embedded within the PDF. One of these URLs, https://nipisod.ru/123?utm_term=alien+vs+predator+extinction+pc++free, is particularly suspicious and likely serves as the primary distribution point for a payload or phishing content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9960
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/123?utm_term=alien+vs+predator+extinction+pc++free
- http://xarapover.mygamesonline.org/xodekakepiguzo.pdf
- https://static.s123-cdn-static.com/uploads/4368951/normal_5feddc61de448.pdf
- http://cardio-natural.info/los_5_lenguajes_del_amor_gary_chapman_gratisag6oj.pdf
- http://50offshop.info/gemilowosanujo9dl7.pdf
- https://wolaserirefuf.weebly.com/uploads/1/3/1/6/131637046/zegezu.pdf
- https://cdn-cms.f-static.net/uploads/4489415/normal_601b82d1bcd6b.pdf
- https://vuguzakinizole.weebly.com/uploads/1/3/4/4/134493236/lajavevefasa.pdf
- https://cdn-cms.f-static.net/uploads/4410702/normal_60215b75492b4.pdf
- http://vexoxem.scienceontheweb.net/boss_monster_portable_pack.pdf
- https://nizovekakajet.weebly.com/uploads/1/3/4/7/134740669/felolujutos-sisumawojawat-tudik.pdf
- https://cdn-cms.f-static.net/uploads/4403672/normal_602288a59c0ac.pdf
- http://fevajubinijexaz.iblogger.org/change_android_mobile_phone_keypad.pdf
- http://homebig.space/crock-pot_sccpvp600-s_smart-pot_6-quart_slow_cookerl5p9r.pdf
- https://kepupumi.weebly.com/uploads/1/3/4/6/134616340/kiludepe-xujeruj-wegeregilab.pdf
- https://cdn-cms.f-static.net/uploads/4450351/normal_6019ce77007db.pdf
- http://fc-aromat.ru/omg_cartoon_20193om4r.pdf
- http://fofifokese.iblogger.org/48701735392.pdf
- http://fasekafalig.scienceontheweb.net/86828455655.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://wiwawilif.epizy.com/sig_sauer_p938_leather_paddle_holster.pdf
- https://s3.amazonaws.com/buwosevax/jersey_shore_florence_twins.pdf
- http://joxepivebafugig.epizy.com/mewosejiwe.pdf
- https://s3.amazonaws.com/rizijubovapuk/92789515425.pdf
- https://s3.amazonaws.com/vexosafugunu/37097152835.pdf
- https://s3.amazonaws.com/wulotugadag/terozoret.pdf
- https://s3.amazonaws.com/gopifu/personality_types_that_dont_get_along.pdf
- http://jedigosegukigif.rf.gd/internal_quality_audit_checklist_template.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f04e.bin9e496114bce2f97e39d57629e272ab675b8a18651cfceaafdb935469a4b79868 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF04E | 5268 bytes |
font_01_sfnt_off00010254.bin6de16725ce5d63008e99e17d647c333beb15954d196f045dcd2a078eeba292f2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10254 | 10240 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.