MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/award?keyword=brief+answers+to+the+big+questions+pdf+free+online PDF link annotation
- https://cdn-cms.f-static.net/uploads/4373248/normal_601717c72f4c1.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4375194/normal_60226f21c4806.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4426820/normal_600f77dc9d653.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4467564/normal_5ffbb0723c667.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4419437/normal_6013b61d78954.pdfIn PDF document text
- http://dimozakebaba.scienceontheweb.net/why_my_epson_l120_not_printing.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4458125/normal_5fd80da73cb53.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4401716/normal_604d1c6d0d294.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4370052/normal_604fb9bd2a7c9.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4475730/normal_6015fdbc327ae.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4426425/normal_603d357e2586b.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4393502/normal_600da51287703.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4390057/normal_603e3e03e5c31.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://zasuwunal.myartsonline.com/87599938668.pdfIn PDF document text
- https://s3.amazonaws.com/muvazi/bovine_spongiform_encephalopathy_test.pdfIn PDF document text
- https://s3.amazonaws.com/sebunuzu/anno_1404_gold_edition_spolszczenie.pdfIn PDF document text
- https://s3.amazonaws.com/kesumasaka/59628566458.pdfIn PDF document text
- http://nupuzawov.onlinewebshop.net/medical_dictionary_french_english.pdfIn PDF document text
- https://s3.amazonaws.com/kikunojulejuj/baidu_wifi_hotspot_free_for_pc.pdfIn PDF document text
- http://bejanifezilo.atwebpages.com/au_bal_masqu_paroles.pdfIn PDF document text
- https://s3.amazonaws.com/viregujipowuru/38881028074.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000107f7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x107F7 | 5712 bytes |
SHA-256: eaae9b5b51aac8c3d714b9e81edcf23ef2de448e822033d50f31ab0b69d19775 |
|||
font_01_sfnt_off00011b66.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11B66 | 12472 bytes |
SHA-256: 330039c8d4dee93449d9b96a4b72b93a80987633d01545e4c7adcf9a8fadcc19 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.