MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged as malicious by a machine learning classifier and ClamAV. It contains an embedded URL that mimics a search query, likely intended to trick the user into visiting a malicious site. The document body, though heavily obfuscated, contains metadata related to its creation, suggesting it was generated by wkhtmltopdf.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/aws?utm_term=zombie+apocalypse+movies+on+netflix+canada
- http://khanapoorti.com/nosatyfz65.pdf
- http://forexgeeks.net/36361528068kgigo.pdf
- http://roxelejabojafe.scienceontheweb.net/merchant_of_venice_sparknotes_act_3.pdf
- http://tetoxukipim.getenjoyment.net/35329483134.pdf
- http://reform-st.ru/suny_wcc_faculty_emailge5or.pdf
- http://brettlockhart.com/maze_runner_book_5_summary4g3ar.pdf
- http://my-favshopf.online/senesefo8begv.pdf
- https://cdn.sqhk.co/benibavagoge/df1ozje/joroluxarokijoxiwilu.pdf
- http://frontglass.xyz/legacy_of_discord_vip_guide6sny0.pdf
- http://proba7.xyz/to_kill_a_mockingbird_journal_entriesqvb9j.pdf
- https://cdn.sqhk.co/xurajalijok/icUYyha/jewobiwepaterefipikifen.pdf
- https://cdn.sqhk.co/bevoroxur/OiihAhd/business_games_pc_online_download.pdf
- https://cdn.sqhk.co/vasinabew/jeicWhd/76128767141.pdf
- http://keepqifi.space/33791698317247sf.pdf
- http://consequences.space/49863633733p7jht.pdf
- http://zikapipumimapo.22web.org/answers_for_what_are_your_strengths.pdf
- http://segwaywheelchair.ru/90813818281vfhih.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://femomebokubogom.epizy.com/lujalimuvokaz.pdf
- http://kuwixogup.rf.gd/cesarean_delivery_operative_report.pdf
- http://mevuxuru.atwebpages.com/woxusalatuvalogarumukop.pdf
- http://wupidusujimi.myartsonline.com/zigewo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e75c.bin4c34209b9513630d096a01c12c61a5dceeed1d574b1269046b854f57b9035fb6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE75C | 5532 bytes |
font_01_sfnt_off0000fa33.binea97253630b4cefbe2672677fb3f3fbaaba91d2d141263f6eb25c684165405db |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA33 | 11116 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.