MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an external URI pointing to 'bologen.ru' which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to a datasheet, indicating a social engineering attempt to trick the user into downloading a payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://bologen.ru/award?keyword=atmega32a+datasheet+pdf PDF link annotation
- http://rigovutamejebum.iblogger.org/gewedepanewukitoro.pdfIn PDF document text
- https://cdn.sqhk.co/xubuzivo/zjeggja/ladev.pdfIn PDF document text
- https://cdn.sqhk.co/pufuxogife/dhdTRF8/nusexe.pdfIn PDF document text
- https://cdn.sqhk.co/jubawiwa/zdMhcIO/ordinal_data_analysis.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://s3.amazonaws.com/gonafoziguwewe/black_administration_act_38_0f_1927.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c800fef9-1f62-436c-a3a6-94fc1a6fee72/compare_3nf_and_bcnf_in_rdbms.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bf7eef86-921b-4211-a980-fa2509eab230/88823895928.pdfIn PDF document text
- https://s3.amazonaws.com/bupesejirijejus/android_9_pie_for_mate_10_lite.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2da6e861-0770-4068-bece-4b3d2a97c1d7/how_to_program_remote_rc122.pdfIn PDF document text
- https://s3.amazonaws.com/muvojugejoxip/6597362041.pdfIn PDF document text
- http://futifuzofu.rf.gd/jorge_luis_borges_books.pdfIn PDF document text
- https://s3.amazonaws.com/lewuli/paxofezunonagujaferiguja.pdfIn PDF document text
- https://s3.amazonaws.com/wulotugadag/bk_precision_8540_service_manual.pdfIn PDF document text
- http://janevaxibeju.rf.gd/39634114286.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/def15fda-8ed4-4a60-a468-849b827eb265/rilukatofumexokizobelavur.pdfIn PDF document text
- http://vipovanur.epizy.com/99951095555.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ae5f2d12-db87-4ccc-acbd-d7612f54beb7/what_are_the_seven_levels_of_hell.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8a703b01-bb91-466a-bcbb-d69942d54c32/34013291594.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e01f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE01F | 5136 bytes |
SHA-256: c59b467a5f6ab6b5a33e661d73971b5879316a91af0680165f84ac57584c022d |
|||
font_01_sfnt_off0000f1a0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1A0 | 10572 bytes |
SHA-256: 54962c38cd5521355735ce13dddb755a39707e10ae1ba1da19efe35dba549ff9 |
|||
font_02_sfnt_off0001159b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1159B | 4324 bytes |
SHA-256: cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.