MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. The document body, though heavily obfuscated, contains text related to 'The Crown season 5 episode 1 review', suggesting a lure to entice users. Embedded URLs point to potentially malicious or compromised sites, which could host further stages of the attack.
Machine Learning
- Nyx PDF Classifier malicious score 0.9311
Heuristics 3
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ambrose.edu/sites/default/files/webform/kubuxodadiwozubak.pdf
- http://oaklandchildcare.org/sites/default/files/webform/dakorudi.pdf
- https://www.mainephilanthropy.org/sites/default/files/kimakevenowafuxopepasu.pdf
- https://www.telluridescience.org/sites/default/files/tstc-applications/nuwirofu.pdf
- http://www.pbttphtk.gov.my/sites/default/files/webform/74795851198.pdf
- https://www.osgeurope.com/sites/osg-corporate.dev/files/webform/35757612566.pdf
- https://aboss.by/sites/default/files/webform/8474239295.pdf
- https://www.a1touchsolution.nl/sites/default/files/43963154407.pdf
- https://vectorcorp.net/sites/default/files/webform/resume/dutaberapowuniz.pdf
- https://www.mothercare.ro/sites/default/files/webform/resumes/77861868930.pdf
- https://www.dgs-interparts.be/sites/default/files/36138637258.pdf
- http://www.guninetwork.org/system/files/webform/heirri_proposals/zarogoluvesiriwameb.pdf
- https://feedproxy.google.com/~r/skout/mBVl/~3/1KS0DP0cxss/uplcv?utm_term=the+crown+season+5+episode+1+review
- https://lib.asu.edu/system/files/webform/46247033309.pdf
- https://printandmail.princeton.edu/system/files/webform/ziwilijevugibapuvoboka.pdf
Open this report in the interactive analyzer, or submit your own file for analysis.