MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file is a PDF document that contains an embedded URL pointing to a suspicious domain. The ML classifier and ClamAV detection strongly indicate maliciousness, classifying it as a phishing trojan. The document body, though heavily obfuscated, suggests a lure related to 'Gym exercise book pdf'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9967
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=gym+exercise+book+pdf
- http://mabirimelu.iblogger.org/detipobegagofi.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/5bc95fc8-377b-4026-a39e-652c542b4fd7/discrete_mathematical_structures_with_applications_to_computer_science.pdf
- https://uploads.strikinglycdn.com/files/7b49f410-7af8-4ae7-8011-b0170626fa2f/sofowosotudasewo.pdf
- https://uploads.strikinglycdn.com/files/2fedbf39-145c-43b0-8fa8-a13c37f9ecd1/how_to_teach_senses_to_grade_1.pdf
- http://nolapejaselijak.epizy.com/aspen_hysys_8._8_tutorial.pdf
- https://uploads.strikinglycdn.com/files/76fafb5c-a035-421f-a760-3c948a3c6a6c/52005454649.pdf
- https://uploads.strikinglycdn.com/files/110a20ff-01d7-499f-86c7-9e9e45a21d2f/vamiripuken.pdf
- https://uploads.strikinglycdn.com/files/948fbaa6-420e-4077-933b-3e1d95fc9772/pufexobakuferop.pdf
- http://lagamifex.epizy.com/skyline_camper_trailer.pdf
- https://uploads.strikinglycdn.com/files/d86dd6d4-e25c-4fdf-ba24-8794b95f71e5/be_the_centre_michael_frye_lyrics.pdf
- https://uploads.strikinglycdn.com/files/5ffec4a5-1b5e-48f4-9fde-f53ac706034b/how_to_take_apart_ingenuity_automatic_bouncer.pdf
- https://uploads.strikinglycdn.com/files/1c8b7697-0eff-4753-857c-598ca84ae5df/25383917142.pdf
- https://uploads.strikinglycdn.com/files/f61d33c1-9dc1-499e-b456-6f7fcdaa3c9c/34208744316.pdf
- https://uploads.strikinglycdn.com/files/88b713da-4014-4043-b311-1505bf9cda0f/zorodof.pdf
- https://uploads.strikinglycdn.com/files/60aa4ff3-b7e2-4196-9b92-a7d88619e666/zosafi.pdf
- https://uploads.strikinglycdn.com/files/77971817-eac4-4f2d-beb9-ddf378608eb7/dawilibefasowokosipowiv.pdf
- https://uploads.strikinglycdn.com/files/ce740cd4-ec0c-4ff5-9e20-ea454cbabc58/big_green_egg_pork_chops_cooking_time.pdf
- https://uploads.strikinglycdn.com/files/3ba0a1d4-fef9-4e11-8460-472a7f133044/classic_horror_short_stories_online.pdf
- http://dunevuzubodofot.rf.gd/clases_de_canto_para_principiantes.pdf
- https://uploads.strikinglycdn.com/files/8792aaf6-070f-4383-b950-c43830ae9a9a/google_how_cold_is_it_outside_right_now.pdf
- http://zozafiromilofin.epizy.com/accounting_for_management_book_anna_university.pdf
- https://uploads.strikinglycdn.com/files/cb90bf5e-0cdd-4cbc-9728-9d94b3a79bb2/nadotezekugutozi.pdf
- https://uploads.strikinglycdn.com/files/26c97d51-d476-4f8c-ac2b-cb48fea296e1/lights_out_windows_home_server_2011_download.pdf
- https://uploads.strikinglycdn.com/files/30945b18-51e5-4411-bdf1-7ea3f110d19e/the_hunger_games_mockingjay_part_2_netflix_release_date.pdf
- https://uploads.strikinglycdn.com/files/7043aa45-ad94-4136-8863-b408f59c5d44/finar.pdf
- https://uploads.strikinglycdn.com/files/6bccb5e0-9a1d-457a-a9c2-d4f067d6f47a/c_primer_plus_6th_edition_exercise_solutions.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001122f.bin5670fa5ab5d092eeab93faaa251129969398e1e1d084adb6d9567b63bee575a8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1122F | 5464 bytes |
font_01_sfnt_off000124c3.bin05fd267dda7013b39de15a070fb8a9ad8d5800b37769e6e640ce347410a27cf8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x124C3 | 10996 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.