MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9843
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/strik?utm_term=prodigy+damage+hack PDF link annotation
- https://cdn-cms.f-static.net/uploads/4496602/normal_6060202c481c1.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4373511/normal_606ccf37e0936.pdfIn PDF document text
- http://pujipaxubeko.22web.org/4102165512.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://fedorahosted.org/lohitIn PDF document text
- https://uploads.strikinglycdn.com/files/87cb404c-cf7f-4195-99b1-6087cb58c73c/the_untethered_soul_the_journey_beyond_yourself_epub.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1c433d65-d2ff-455d-9814-40f7fbacf177/what_does_boast_mean_for_birds.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/117888ad-7761-41f0-b08c-fdbdd8ef9d2c/cradle_to_cradle_certification_logo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/21c69084-f5f7-4fd2-842c-9dc07cefd792/how_to_make_fruit_wine_at_home_step_by_step.pdfIn PDF document text
- http://bapaxofobawob.rf.gd/42920865539.pdfIn PDF document text
- http://dodadaxijer.epizy.com/bar_graph_analysis_worksheets.pdfIn PDF document text
- http://nadezuj.epizy.com/writing_down_the_bones_free_download.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a44528e5-29e1-4249-b88a-c73ec50dcbc0/white_rodgers_thermostat_reset_1f80-261.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d235fd8a-4c34-44c2-bde5-5d0833685c0f/guzogoz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/defa819e-2bc5-4d81-9ee0-3f323ad18259/pumozawogejepugow.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/549ba0f9-75b4-4611-bdce-6d9ff6446ab0/what_is_the_safest_plane_company.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e6841627-c32d-465a-9be0-216e12ea6d3b/best_vegetarian_recipes_for_losing_weight.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d68044f4-3bb1-40d6-8535-05c9f712324e/bushnell_binoculars_repair_parts.pdfIn PDF document text
- http://masegopadi.epizy.com/vocabulary_workshop_level_b_unit_4_literary_text_answers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a31d76d7-63aa-442a-93e4-7047de8a67ee/18557638899.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00017668.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x17668 | 4100 bytes |
SHA-256: d8c3a3007445f087e93e06bd5abce4443baf2f5090b37702be265806555f9433 |
|||
font_01_sfnt_off00018523.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18523 | 5308 bytes |
SHA-256: 495f8a68a1640321da3137080327ea17dbdcb73b3061388d250c0ce6a49e6950 |
|||
font_02_sfnt_off0001970e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1970E | 2316 bytes |
SHA-256: 5636d8d5fdd5a113ad317891756ad04021119b75fdafbfd8e21eb483790aa3d8 |
|||
font_03_sfnt_off0001a0f6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A0F6 | 3788 bytes |
SHA-256: af5c02dea5313c26b5f9c173c5aae780ee5f91a3363c239578d5bcd7018c06f6 |
|||
font_04_sfnt_off0001b04a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1B04A | 15480 bytes |
SHA-256: 12ac0190e75ac230f9793fe2e57ab077c3a16918c787f92a0aff06c0db86fa09 |
|||
font_05_sfnt_off0001e0da.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E0DA | 17296 bytes |
SHA-256: 2d351f8d38d3e3218ba5e7d1ed14b218b938514ad08f2071d73282cd57807de3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.