MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains an embedded URL that directs users to a suspicious domain, disguised as a resource for IELTS general writing topics. This URL is likely intended to lead the user to a phishing or malware distribution site. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/award?keyword=writing+topics+for+ielts+general+pdf
- https://static.s123-cdn-static.com/uploads/4459796/normal_5fe03ebe2266b.pdf
- https://cdn-cms.f-static.net/uploads/4384851/normal_60483d70150b3.pdf
- http://wusator.mygamesonline.org/free_asvab_study_guide_2020.pdf
- https://static.s123-cdn-static.com/uploads/4385231/normal_5ff28e50e574b.pdf
- https://cdn-cms.f-static.net/uploads/4470218/normal_604db2afde44d.pdf
- https://cdn-cms.f-static.net/uploads/4382773/normal_602a111115875.pdf
- https://cdn-cms.f-static.net/uploads/4491152/normal_6033ea1562447.pdf
- http://suwefazimim.medianewsonline.com/bugubuti.pdf
- https://cdn-cms.f-static.net/uploads/4389384/normal_5fd2ff73da7d7.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://c63ca81c-6df4-4ec3-bc2e-8508f29a6879.filesusr.com/ugd/d48fe3_3cc84a4443fc492a9240062eb20bf230.pdf?index=true
- https://s3.amazonaws.com/jujadodedaruxix/black_widow_song_mr_jatt.pdf
- https://s3.amazonaws.com/gisujubolidine/how_does_boston_market_make_their_mashed_potatoes.pdf
- https://uploads.strikinglycdn.com/files/c845f9b6-8ef6-4b55-8e93-decca9e0553f/how_to_make_a_girl_want_you_and_think_of_you_sexually.pdf
- https://b2f02272-107b-4032-aafc-54cdd6265a16.filesusr.com/ugd/6cf392_7305ff61b26641dd83dd6b66009229e1.pdf?index=true
- https://uploads.strikinglycdn.com/files/47a46c15-54b4-48fd-ba9d-6606213f5309/1684208012.pdf
- https://s3.amazonaws.com/muxozuvalubi/nekovifevokujazedu.pdf
- https://s3.amazonaws.com/mexijegedakol/20983045955.pdf
- https://uploads.strikinglycdn.com/files/2ea1bc66-03f9-487f-a4b4-a634059198f0/create_your_own_small_business_website_free.pdf
- https://98748e4b-3258-471a-903e-8ea98415cca0.filesusr.com/ugd/fd7405_e31287b4073049488ae18d74d8660258.pdf?index=true
- https://uploads.strikinglycdn.com/files/c7283f9c-569f-439c-bcc1-5bc8b6218f43/wordly_wise_3000_book_9_teachers_edition.pdf
- https://4253c66a-660d-4c83-b31d-f715833d547b.filesusr.com/ugd/d9e9a0_16556d9aa73c4c84bc7e10b299a63e67.pdf?index=true
- https://s3.amazonaws.com/gagotaniwipure/42719690955.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fa12.bina51b97a074caa35ee7d44f69b11aef84540a8dece0f23c2f2e9778ac76094837 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA12 | 5336 bytes |
font_01_sfnt_off00010c56.binaeee9b2fd577c594ede074a7e3493832e024aab8d381a7c1d16527c2e435dd06 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10C56 | 2252 bytes |
font_02_sfnt_off00011694.bin9cd7a78f99978134c177ff4f4d33e748f063cb9276598185cab1633aa9a20849 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11694 | 10688 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.