MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ClamAV and an ML classifier, with a heuristic indicating an external URI. The embedded URL 'https://botokaw.ru/award?keyword=eeg+de+sommeil+pdf' suggests a phishing attempt to lure users to a malicious site. While no scripts were explicitly extracted, the PDF format and the nature of the URL point towards a phishing or social engineering attack vector, likely involving embedded JavaScript for redirection or further exploitation.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/award?keyword=eeg+de+sommeil+pdf
- https://cdn.sqhk.co/vafegijateno/ifFhamR/fox_theater_showtimes.pdf
- https://cdn.sqhk.co/kinanekoxo/iilWZic/dipup.pdf
- https://cdn.sqhk.co/votezevon/ggVwgjF/pet_rescue_saga_game_1228.pdf
- https://cdn.sqhk.co/funixatugesi/Pjdhjgd/9730361816.pdf
- http://mifopevoruroga.22web.org/sawuwof.pdf
- https://cdn.sqhk.co/rogekanus/BgdhjiV/84056507099.pdf
- https://cdn.sqhk.co/zimuteraf/ahchTv9/wheel_of_fortune_games_online.pdf
- http://wopexobow.mywebcommunity.org/cpr_latest_guidelines_2020.pdf
- https://cdn.sqhk.co/xusopusavo/jhhjYie/3477068763.pdf
- http://jafoxidulez.mypressonline.com/mesalitekigoguzavisevu.pdf
- https://cdn.sqhk.co/velijituma/jciiulG/web_design_software_adobe_dreamweaver_cc.pdf
- http://wudazex.sportsontheweb.net/pleomorphic_adenoma_review.pdf
- https://cdn.sqhk.co/vuwonesi/0bc8Mib/stick_z_super_dragon_fight_unlimited_money_apk.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/xewamejixolefaj/restaurant_company_profile_sample.pdf
- http://rukosivujuxu.atwebpages.com/13074403385.pdf
- https://s3.amazonaws.com/mujevubutukoxu/les_miserables_broadway_cast_2019.pdf
- https://uploads.strikinglycdn.com/files/64433e74-8870-432b-8625-1df7942f9c08/who_is_project_zorgo_leader.pdf
- https://s3.amazonaws.com/kovozenamofox/ralaxikawozonagizo.pdf
- https://uploads.strikinglycdn.com/files/cf524ec5-a72b-47b6-89e0-0e5fc5c07090/85680165660.pdf
- https://s3.amazonaws.com/tomaxade/natowazozofirawusilud.pdf
- http://dudameridetira.epizy.com/vizapudisemofif.pdf
- https://uploads.strikinglycdn.com/files/600d66ad-d782-4d8b-b59c-4760b2babc2f/john_g_lake_books_drive.pdf
- https://s3.amazonaws.com/wurivuve/restaurant_building_vector_free.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1c5.bin71877a51a1358b2b8bc75052feea371d355a3066ab8b99395751753010670d6c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1C5 | 5012 bytes |
font_01_sfnt_off000102cf.bin78144a4416c3e7c47dd7552a1484db045a174d2aafb7addfbff234c59fa6ac3a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x102CF | 12008 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.