MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The file is identified as malicious by a machine learning classifier and ClamAV, with a specific detection name indicating it is a phishing trojan. The presence of an external URI pointing to 'bologen.ru' and a heuristic for a visual download button suggests a phishing or social engineering lure. The document body, though heavily obfuscated, contains remnants of what appears to be a worksheet title, reinforcing the lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9848
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://bologen.ru/wix?keyword=fluid+pressure+problems+worksheet
- https://cdn.sqhk.co/javijaxim/iMKWwyz/28213826108.pdf
- https://cdn.sqhk.co/gedadixugud/rwgjUmC/capture_one_tutorials.pdf
- https://cdn.sqhk.co/wixexozesila/SjgMif4/20484544913.pdf
- https://cdn.sqhk.co/sewujuzanas/AbihPqo/megan_fox_2020_movies.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://fedorahosted.org/lohit
- https://uploads.strikinglycdn.com/files/aaa6a67d-9bbb-4b5a-a340-f0ffe577e7aa/3d_metal_printing_seminar_ppt.pdf
- https://bef89f6e-6323-4b84-ad9d-a44490bfcc4f.filesusr.com/ugd/96768c_75037947e44d461ab2e7d1e26567c88f.pdf?index=true
- https://814cba0f-f649-4223-bfe6-7884e6e02b9d.filesusr.com/ugd/c1108c_e26d1e98f2e74fa4bc3e958af633a945.pdf?index=true
- https://42190e62-4dca-482d-a077-ae7b222d7779.filesusr.com/ugd/b91392_9a088a9a2c1a4e03a9aa2c46b8c12cbf.pdf?index=true
- https://uploads.strikinglycdn.com/files/c220dab8-87e3-46a4-9064-48cc52449b8b/bose_acoustimass_10_series_v_home_theater_speaker_system.pdf
- https://uploads.strikinglycdn.com/files/e26e2cd7-0a6c-474e-9e16-9e567f37651d/scag_freedom_z_vs_patriot.pdf
- https://cf336f9a-6a79-4542-9269-5b62d6eb69dd.filesusr.com/ugd/1daf83_d4406055e1bc43afb8ddec5c91f8f98c.pdf?index=true
- https://s3.amazonaws.com/mojivikapeti/the_mask_of_the_red_death_theme.pdf
- https://uploads.strikinglycdn.com/files/c27be61e-0ac7-4355-83ba-f03dbaae5b1f/vitamix_smoothie_recipes_with_oranges.pdf
- https://s3.amazonaws.com/zifilobesumafi/46102258392.pdf
- https://uploads.strikinglycdn.com/files/2f9ba9a8-7ec7-4008-ad92-e2307275f9f6/59396837096.pdf
- https://uploads.strikinglycdn.com/files/9b203ffc-8bc4-4670-9e19-5530e931265e/genak.pdf
- https://667abc8f-92ca-45d9-bc9d-789c80a68858.filesusr.com/ugd/dcd78f_5d5137aa755a4a47bdd60501ee7518f5.pdf?index=true
- https://s3.amazonaws.com/fobupojowojon/chrome_browser_free_for_windows_10.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00039a76.binb64ef0855174d3bf81a246d1d4dc8550353a0868db90b90a02a44fb784b8429c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x39A76 | 5240 bytes |
font_01_sfnt_off0003ac28.binc0c950c7790592a7c8371003655615a1ed2f5d16bc3d3cad24fe89a38434518e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3AC28 | 13032 bytes |
font_02_sfnt_off0003d809.binf1e6c85fce0aa041392f1af700af9accdb30870cc252e4f0c1c889d6daf43cb3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3D809 | 2856 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.