MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by a machine learning classifier and ClamAV, indicating a high likelihood of malicious intent. The document body, though heavily obfuscated, contains text suggesting it is a summary of 'Pride and Prejudice', a common lure for phishing or malware delivery. The presence of an external URI pointing to 'jumiwimov.ru' strongly suggests the document is designed to redirect the user to a malicious site, likely for further exploitation or payload download.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/strik?utm_term=pride+and+prejudice+chapter+11-14+summary
- https://cdn-cms.f-static.net/uploads/4387226/normal_603758b34558e.pdf
- https://static.s123-cdn-static.com/uploads/4372963/normal_5fdff1a1e8454.pdf
- https://cdn-cms.f-static.net/uploads/4409602/normal_600aacdf1b5b3.pdf
- https://cdn-cms.f-static.net/uploads/4443819/normal_6059a60b8c6a6.pdf
- https://cdn-cms.f-static.net/uploads/4388421/normal_600cb4d9bde63.pdf
- https://cdn-cms.f-static.net/uploads/4383147/normal_5fe81f8b5a116.pdf
- https://cdn-cms.f-static.net/uploads/4389804/normal_6057fab10a1fe.pdf
- https://cdn-cms.f-static.net/uploads/4486193/normal_6040e3ae37d88.pdf
- https://cdn-cms.f-static.net/uploads/4450415/normal_60338b8c7521e.pdf
- https://static.s123-cdn-static.com/uploads/4392877/normal_5fee9e0781bc6.pdf
- https://static.s123-cdn-static.com/uploads/4495390/normal_5ff1c934206e5.pdf
- https://cdn-cms.f-static.net/uploads/4371014/normal_6024f73954cf0.pdf
- http://volomowoxe.22web.org/74573096616.pdf
- https://cdn-cms.f-static.net/uploads/4383138/normal_603412353bc4f.pdf
- https://cdn-cms.f-static.net/uploads/4489980/normal_605b1cd3d358f.pdf
- https://cdn-cms.f-static.net/uploads/4502436/normal_603a2abb569a2.pdf
- https://static.s123-cdn-static.com/uploads/4426697/normal_5fdd7a68d8aad.pdf
- https://static.s123-cdn-static.com/uploads/4426063/normal_5fe50b717b9f7.pdf
- http://jupulapigivux.22web.org/79294294542.pdf
- https://static.s123-cdn-static.com/uploads/4374022/normal_5ffa94f53b10a.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://nasuxenabo.epizy.com/nepud.pdf
- http://bividit.rf.gd/aegan_tamil_movie_free_in_utorrent.pdf
- http://nibatozov.epizy.com/creative_writing_topics_for_grade_4.pdf
- http://bataxob.rf.gd/gewiku.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010267.bin34f849ab4e1286831986653a2b48c65f3e17c8511847de42e7db322a6e3146a7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10267 | 5632 bytes |
font_01_sfnt_off00011583.bin2c29503248da2151cc5dd69068e329b077292819139b46d5d04e8ba124f6689c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11583 | 9984 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.