MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ML classifiers and ClamAV, with a critical heuristic firing for ClamAV detection. An external URI pointing to 'coretry.ru' was extracted, which is highly suspicious. The document body, though heavily obfuscated, contains strings that suggest a lure related to 'Sims 4 cheats mac fill needs', likely a pretext to drive the user to the malicious URL. No scripts were extracted, but the PDF structure and external URI are strong indicators of a phishing or malware delivery attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://coretry.ru/pbw?utm_term=sims+4+cheats+mac+fill+needs
- https://static.s123-cdn-static.com/uploads/4529095/normal_5ff9bd298e591.pdf
- https://cdn-cms.f-static.net/uploads/4383300/normal_5fda89d51a135.pdf
- https://cdn-cms.f-static.net/uploads/4407100/normal_6038edafc70d9.pdf
- https://cdn-cms.f-static.net/uploads/4464303/normal_5fe6734b0b70e.pdf
- https://static.s123-cdn-static.com/uploads/4476432/normal_5fca7787e61a9.pdf
- https://cdn-cms.f-static.net/uploads/4530846/normal_5fe8dddf618d7.pdf
- https://cdn-cms.f-static.net/uploads/4387814/normal_605584e515bc8.pdf
- https://static.s123-cdn-static.com/uploads/4475729/normal_5ffe80acce1ea.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/08978ec8-bfb7-4e67-86a8-82efb2a74e37/17810473572.pdf
- http://jisopubo.pbworks.com/f/45370680974.pdf
- https://uploads.strikinglycdn.com/files/e9c5cff5-d440-4fd5-8e8b-b134cb9d1bc5/78978835339.pdf
- http://gafuxexosaru.pbworks.com/w/file/fetch/145001646/the_cuckoos_calling_download.pdf
- https://uploads.strikinglycdn.com/files/522b22ba-469f-44e0-a529-2c1e9000a810/vobike.pdf
- https://uploads.strikinglycdn.com/files/b9f26c90-7821-4282-b650-2933394ea017/formulas_para_calcular_areas_y_perimetros_de_figuras_geometricas.pdf
- http://nusometa.pbworks.com/f/dizurasajimoxufeviv.pdf
- https://uploads.strikinglycdn.com/files/bbb7b284-5d6d-4efa-b5ed-5c66d3ea6e9f/canon_pixma_mx922_reviews.pdf
- http://tereburokofe.pbworks.com/w/file/fetch/145172901/2838441520.pdf
- https://uploads.strikinglycdn.com/files/19277d9b-211b-4191-bbd5-4b091a8f9238/sirizoluruva.pdf
- http://kakexigodelo.pbworks.com/w/file/fetch/144575778/what_is_the_difference_between_convex_and_concave_lens.pdf
- https://uploads.strikinglycdn.com/files/764d775f-1755-4578-8c50-a93b91636485/different_sexual_orientation_synonyms.pdf
- https://uploads.strikinglycdn.com/files/57544ece-cd78-40f7-9161-fdf79587088c/pathoma_2018_free.pdf
- https://uploads.strikinglycdn.com/files/5900c584-4275-4e7f-8327-fdcb39a261a0/68566481393.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://savannah.gnu.org/projects/freefont/
- http://www.gnu.org/licenses/
- http://www.gnu.org/copyleft/gpl.html
- http://scripts.sil.org/OFL
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000162d2.bin526c5a2175551476bef9e67e23fc16d118bda5f5d89964818a68e3a853678add |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x162D2 | 6476 bytes |
font_01_sfnt_off000172d9.bin61378367bac1bfb79c3e69585fa6f753b21628056cf4e189360023530ce0d413 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x172D9 | 5356 bytes |
font_02_sfnt_off000184ef.bindfab3945eace5ba27be1ad95d63d5142397767eab6bca27773794b33bda2302c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x184EF | 1796 bytes |
font_03_sfnt_off00018d79.bin5eb6c4027d901a7f487318667b5fe1b9439f4a959683be5978e58cf9a9504ac5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18D79 | 12600 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.