MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to trick the user into downloading a malicious payload. The document body, though heavily obfuscated, suggests a lure related to 'anger management workbook and curriculum pdf'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/award?keyword=anger+management+workbook+and+curriculum+pdf
- http://vopagokiniki.mypressonline.com/zavinowotudefofivexakuj.pdf
- http://lnstagram-blue-badge-form.com/what_is_the_meaning_of_interstate_trade_and_commercext0o1.pdf
- http://wedipum.mygamesonline.org/war_horse_cast_list.pdf
- http://gikadoketu.iblogger.org/tin_tin_restaurant_aguadilla.pdf
- http://cashtanks.fun/zogawamarofedaf7bfy9.pdf
- http://pitikudefojeken.getenjoyment.net/pdf_candy_desktop_key.pdf
- http://nigoguno.scienceontheweb.net/68219277644.pdf
- http://wubowobipevoto.mywebcommunity.org/what_are_the_traits_of_a_sensitive_person.pdf
- http://kusafomidufe.mywebcommunity.org/guide_to_intermittent_fasting.pdf
- http://lokotahas.ru/dr_nelson_pediatrician6f3br.pdf
- http://jidokove.scienceontheweb.net/what_are_the_biggest_brokerage_firms.pdf
- http://baxemoge.iblogger.org/gbrmpa_water_quality_guidelines.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- http://gipebevu.atwebpages.com/75148057454.pdf
- http://fetelezazojidi.rf.gd/bloomberg_barclays_global_aggregate_index.pdf
- http://ripeterub.epizy.com/zowenigewajofolejipaganom.pdf
- http://musovinudebepak.epizy.com/vigejuxinewujiralumuretip.pdf
- http://fonunegemo.epizy.com/alexa_app_for_iphone.pdf
- http://kirojera.rf.gd/21800839871.pdf
- http://rozejogore.rf.gd/warlock_5e_patrons_great_old_one.pdf
- http://likasiz.epizy.com/41085571930.pdf
- http://ritumogadoj.onlinewebshop.net/ps4_controller_walmart.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001062e.binefba441987161f79b49605918397f732c1a42291a7be71022a0eda596cb1ea7c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1062E | 5464 bytes |
font_01_sfnt_off000118b5.bin1fba2284fbc193a1584d9bf9fde628f915d1beca64406fad22e48b17d59ea90d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x118B5 | 11336 bytes |
font_02_sfnt_off00013fa0.bine93acd332f5893643511f4cefd38969ad5c744ad1b08842a788b6be7d277dd15 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13FA0 | 16204 bytes |
font_03_sfnt_off000154ce.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x154CE | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.