MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged as malicious by a machine learning classifier and ClamAV. It contains language suggestive of an invoice or payment lure, and embeds a URL that likely leads to a malicious payload. While no scripts were directly extracted, the PDF structure and embedded URI indicate a phishing attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://golowaki.ru/123?utm_term=amadeus+reissue+commands+pdf
- https://benokonafininu.weebly.com/uploads/1/3/4/6/134606635/3411404.pdf
- https://static.s123-cdn-static.com/uploads/4449605/normal_5fffb62929f59.pdf
- http://jiludedo.iblogger.org/94038678602.pdf
- http://fuxejezosajusop.22web.org/organizational_structure_template_online.pdf
- https://cdn-cms.f-static.net/uploads/4455183/normal_604ca28aa3a13.pdf
- https://goguribepolim.weebly.com/uploads/1/3/0/7/130739596/17cb9ee065e2b05.pdf
- https://cdn-cms.f-static.net/uploads/4480149/normal_6019a40f31421.pdf
- https://cdn-cms.f-static.net/uploads/4481278/normal_6021a564f28d9.pdf
- http://newuwedeza.mypressonline.com/bedtime_stories_read_along.pdf
- https://static.s123-cdn-static.com/uploads/4453914/normal_5ff7e12574b0e.pdf
- https://geguxawuxereko.weebly.com/uploads/1/3/1/3/131379712/doxubi.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://ab60d57a-1f92-408f-9079-0b325776b613.filesusr.com/ugd/724fb5_07856c41f21e43bfae5a8e7aa36636a4.pdf?index=true
- https://s3.amazonaws.com/bisazabe/voxij.pdf
- https://26f2e344-8444-46ea-90c9-5a893bcc2fb3.filesusr.com/ugd/b8c837_ebabae8d79f14830a9949fcca09e8598.pdf?index=true
- https://s3.amazonaws.com/lanorolowu/vizolenewedeja.pdf
- https://s3.amazonaws.com/bupaxomu/78278650683.pdf
- http://kikanelomer.onlinewebshop.net/20122923882.pdf
- http://gumigojozupe.epizy.com/georgia_power_bill_template.pdf
- http://lamuverifob.epizy.com/siwukoxalujodofopogugoz.pdf
- https://s3.amazonaws.com/selivuvumepaveb/fz_bike_200_cc_price.pdf
- https://25f35837-e8ad-4357-b490-8f69bec4165a.filesusr.com/ugd/96c61c_ad20bcda9d2e4cca956361cfcf2f4b8e.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001ca25.bin440fab83cc750dc954eef927fa1159f498d5ef06a455bd716ebcaf55c9793bd6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1CA25 | 5060 bytes |
font_01_sfnt_off0001db2e.bin6fb02298af4ace3d305a42fb98ecf144db66fade51d854cf90390964a8ab7dfd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1DB2E | 11092 bytes |
font_02_sfnt_off00020100.bin05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x20100 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.