MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URI that leads to a malicious URL, likely intended to trick the user into downloading a further malicious payload. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://laborke.ru/uplcv?utm_term=catholic+devotional+prayer+book+pdf
- http://endustriyelkiralama.com/wp-content/plugins/super-forms/uploads/php/files/vdc6g938123g3g84mi9nmg606d/25108829654.pdf
- https://amirep.com/wp-content/plugins/super-forms/uploads/php/files/0ea1ac2e604b3f85c00bcd5d813d0fb0/67983937008.pdf
- http://yuha.be/_files/file/disefosaxasuzozezalesene.pdf
- https://www.carlosfunes.es/wp-content/plugins/formcraft/file-upload/server/content/files/160a578e00779d---99082681687.pdf
- http://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/5ba266ed351a018d31b55c504c08ec84/powuza.pdf
- https://almondzwealth.com/administrator/imagetemp/file/kobefojafog.pdf
- http://lycee-elm.org/userfiles/file/woruzimepok.pdf
- https://www.actionconstructionjax.com/wp-content/plugins/super-forms/uploads/php/files/0c314d158859b725ca8008229346aa2c/58977576187.pdf
- https://pankalconstructora.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609b1f3d5bc7d---xomemun.pdf
- https://www.fifatravels.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093357b4bfa6---59550696134.pdf
- https://123kozijnofferte.nl/wp-content/plugins/super-forms/uploads/php/files/tjktdarj0018c9svdld4mn6qc6/burivopam.pdf
- http://anhuizhkj.com/upload_fck/file/2021-5-8/20210508055110622342.pdf
- http://chixue.com/uploadfile/file/20210522045733.pdf
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609be1b7c6e62---3921016099.pdf
- https://ohligschlaeger-berger.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609df209c0a12---482609497.pdf
- https://pinotcar.com/wp-content/plugins/super-forms/uploads/php/files/08adb672c44be698fb9384e614459882/nijifaruwimarigafol.pdf
- https://pilotcenter.gr/wp-content/plugins/super-forms/uploads/php/files/vhcmnbvenkcaobs25j9gbq61sp/kedelubafi.pdf
- http://www.alex-vasilkov.ru/images/wisdom/file/26727629655.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d2eb.bine6fa9352acf935b31f90ca4bc3c1f6c6682febae845da362c449f72fe4484dd1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD2EB | 5336 bytes |
font_01_sfnt_off0000e514.bin7e1a2990cf1ec08506306ccae7f0658c32024ea1865b05ad8ea7e731286e6c9c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE514 | 10264 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.