MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The document body, though heavily obfuscated, suggests a lure related to scientific information, which is a common tactic for social engineering.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/strik?utm_term=how+to+determine+boiling+point+of+ethanol PDF link annotation
- https://cdn.sqhk.co/ninilevikod/wggjijj/zewefezexipikut.pdfIn PDF document text
- https://cdn.sqhk.co/feletitami/Rejaija/bonbon_cakery_mod_2._1._10.pdfIn PDF document text
- https://cdn.sqhk.co/dukoredod/6hb6ibu/85385330549.pdfIn PDF document text
- http://kevikakagax.iblogger.org/98809183040.pdfIn PDF document text
- https://cdn.sqhk.co/vizefejij/khgLhii/suladonisuxef.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/fosawef/vuxilubevuvovopifubude.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5726b629-4ceb-48f0-a737-524b9389dae4/niganenegotik.pdfIn PDF document text
- http://bapomel.epizy.com/sembaruthi_serial_songs_in_tamil_isaimini.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8bd0d0bc-a22a-4c41-b2ec-6599060b7c9a/what_does_the_tree_of_life_mean_in_revelation_22.pdfIn PDF document text
- https://s3.amazonaws.com/dumupa/62537042915.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0d4c50d6-a784-442e-85df-96a9c93c8ae2/echo_studio_user_manual.pdfIn PDF document text
- http://xulodolab.epizy.com/ek_waqia_batlata_hoon_naat.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ae8280b6-ce76-45e0-92f9-41ae16b3d865/28644541573.pdfIn PDF document text
- https://s3.amazonaws.com/pesetufavo/what_is_the_synopsis_of_les_miserables.pdfIn PDF document text
- https://s3.amazonaws.com/tiluwisulepam/63633000219.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/35695916-a016-4a96-85bd-a38ab1f19993/systematic_literature_review_conclusion.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/58a5bc86-341b-436f-a72d-3870cee6175e/omron_body_composition_monitor_with_scale_bluetooth.pdfIn PDF document text
- http://gujitijeko.rf.gd/momofufotamavuloparajiz.pdfIn PDF document text
- https://s3.amazonaws.com/lovetijif/22310372354.pdfIn PDF document text
- https://s3.amazonaws.com/votubukaxogilix/46730865224.pdfIn PDF document text
- https://s3.amazonaws.com/jadudusujuje/absence_letter_format_for_university.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e882.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE882 | 2900 bytes |
SHA-256: b3dfb2f2c41da7350fc3755141d2fd0ea5796bb125df25fec831093623ff73df |
|||
font_01_sfnt_off0000f2c5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF2C5 | 5468 bytes |
SHA-256: 9afb0246ddd848b8def2236accdd9f030b5cefec9a13f722de0b91db76ff489a |
|||
font_02_sfnt_off0001053c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1053C | 11424 bytes |
SHA-256: 32c4509dba353b0b6d1c457fb70c7a5be5220cab13ea4e4175aab215dae3683d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.