MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URL that redirects to a malicious domain, likely to deliver a phishing lure or a secondary payload. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest it's designed to trick users into visiting a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9989
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/wix?keyword=gene+expression+transcription+answer+key+pdf
- http://instasurprise.online/koxigekajozumired24ajz.pdf
- http://uscreditmonitoring.info/netujux6vw7h.pdf
- http://copyright-supporthelp.com/how_do_you_say_tell_me_about_yourself_in_spanishfhm73.pdf
- https://kupolagaxex.weebly.com/uploads/1/3/0/9/130969851/613292.pdf
- http://rafupofamurawaf.mygamesonline.org/73792483528.pdf
- http://masito.space/pitipukodexon6vevm.pdf
- https://cdn.sqhk.co/vifejoneses/hcgcYhI/pmi_lessons_learned_template_free.pdf
- http://tufuwavaziga.mygamesonline.org/53283043741.pdf
- https://cdn.sqhk.co/dopuzodopuvu/jteqThg/android_8_dbz_wiki.pdf
- https://gapojusegora.weebly.com/uploads/1/3/1/4/131408170/woxoz-xetesozumatesa-wibomaxajubo.pdf
- http://kiwenalod.medianewsonline.com/kitof.pdf
- http://otshelnik.net/9959456147033vz3.pdf
- http://meetsoda.club/brother_printer_5450dn_drum_error7e6ab.pdf
- https://dirotigakavomak.weebly.com/uploads/1/3/4/2/134235834/zegavepe-xuxigev-jupebod.pdf
- https://cdn.sqhk.co/kagalitisup/hhvihM0/supertuxkart_0._9_3_download.pdf
- https://kefagifugujog.weebly.com/uploads/1/3/0/8/130813645/tawipo_juxekogerijefu_pukezasi_limuwezebuwa.pdf
- http://1green.space/frosty_the_snowman_song_lyrics1fbm4.pdf
- http://natlegend.space/fodmap_food_list_ukvcsv9.pdf
- https://cdn-cms.f-static.net/uploads/4454973/normal_6031961e2b337.pdf
- https://cdn-cms.f-static.net/uploads/4501046/normal_603ee26bd70d0.pdf
- http://fosipuzo.mypressonline.com/how_many_miles_can_a_honda_rebel_250_last.pdf
- https://cdn-cms.f-static.net/uploads/4413111/normal_604f0bf194ee7.pdf
- https://sigurapefudaji.weebly.com/uploads/1/3/4/5/134576843/xolojezabu.pdf
- https://cdn.sqhk.co/ripudilibizo/fvgfjgl/nedoxetuxixa.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- http://widepidaba.atwebpages.com/mijukur.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000107b7.binb99c62a4d3ac8126c6e4052793e1419a8c450e4df412ea614d66238a7976c638 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x107B7 | 5260 bytes |
font_01_sfnt_off000119cc.binba8c0c3d4c73575def299cc749c9898816618d3b30c65e027021832b16928125 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x119CC | 13268 bytes |
font_02_sfnt_off00014495.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14495 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.