MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains an embedded URI pointing to a suspicious domain, likely intended to deliver a secondary payload or redirect the user to a malicious site. The document body, though heavily obfuscated, contains keywords related to product names, suggesting a lure to a fake product page.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/strik?utm_term=hayward+h400fdn+gas+valve
- http://xumupizaxuto.scienceontheweb.net/12972917192.pdf
- http://punavuvipufov.sportsontheweb.net/how_to_learn_linux_kernel.pdf
- http://mizizufiku.mywebcommunity.org/vuderenapowa.pdf
- http://kavuxolabazili.iblogger.org/easy_anti_cheat_watch_dogs_2.pdf
- http://bometaximom.scienceontheweb.net/nulanamozuzugawituv.pdf
- http://zakomuxoza.getenjoyment.net/how_do_i_pair_my_old_xfinity_remote_with_my_tv.pdf
- http://vogolimipogusoz.mypressonline.com/35066744551.pdf
- http://net-klientov.ru/what_is_knowledge_work_systemyes4d.pdf
- http://gimatadokij.mygamesonline.org/gataxixaxu.pdf
- http://replyua.site/gituvofedufuruwavizot2le2.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.opentle.org
- https://11ca5eb4-0abe-4d5d-8073-3f36f6088e80.filesusr.com/ugd/8b62d8_cc24a4b1281342f79cf8c4e0ea95eefa.pdf?index=true
- http://jokubamobivavum.onlinewebshop.net/nolejugag.pdf
- https://e5acd528-9925-4355-98ed-6c6122c9c19a.filesusr.com/ugd/49fecd_e1218c257f244235b6e7fa037f71c2cc.pdf?index=true
- http://zigakakedulogim.myartsonline.com/nasuzaralirez.pdf
- http://matewedidoxeber.onlinewebshop.net/31911824750.pdf
- https://59bb578d-b312-442a-858b-1a1a54b18a6c.filesusr.com/ugd/c79b1c_348b0ce29f2b41558e949b9527a3d7e8.pdf?index=true
- https://8f20b4bd-83f7-4a55-8c6f-e9501e2e061c.filesusr.com/ugd/c1c462_3be7bae68f25473699467e020093b9f4.pdf?index=true
- https://e082b6be-64c0-45f6-a8ff-82b9c6f476f0.filesusr.com/ugd/1479de_e9ab64cfcf5d4f40bedfc448a89692cc.pdf?index=true
- http://vojilub.rf.gd/introduction_of_interview_report_sample.pdf
- http://pogebikaku.epizy.com/golidos.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://www.gnu.org/licenses/gpl.html
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e1be.binaceb053cb6002deffe404e78e7a3ccca6362090cded6454b583aebed90e18fac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE1BE | 5612 bytes |
font_01_sfnt_off0000f4ed.bina36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF4ED | 1800 bytes |
font_02_sfnt_off0000fd6f.bin090901b69189ba7e8f9d7ae4d434dc1f4dfb0b984875fd853fcdff436a366447 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFD6F | 7432 bytes |
font_03_sfnt_off0001118a.bin5b523d3c68753cbf2d558d4295cb5735ee8c019ae2a9d49e800886af76fd272e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1118A | 11436 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.