MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan payload. It contains an embedded URI pointing to a suspicious domain, likely intended to deliver a secondary malicious payload or redirect the user to a phishing site. The document body, though heavily obfuscated, suggests a lure related to appliance troubleshooting.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/strik?utm_term=how+to+reset+a+whirlpool+dishwasher+quiet+partner+ii
- https://cdn-cms.f-static.net/uploads/4489056/normal_6051eeaa392a8.pdf
- https://cdn-cms.f-static.net/uploads/4426543/normal_6035b918597fd.pdf
- https://cdn-cms.f-static.net/uploads/4498345/normal_60530ee29aafb.pdf
- https://static.s123-cdn-static.com/uploads/4424692/normal_60033a7324c94.pdf
- https://cdn-cms.f-static.net/uploads/4417325/normal_605db73a498f1.pdf
- http://dagomakiluje.iblogger.org/fovusomonamatomovigokep.pdf
- http://javatow.22web.org/73096695205.pdf
- https://cdn-cms.f-static.net/uploads/4413363/normal_600b504843acd.pdf
- https://cdn-cms.f-static.net/uploads/4409258/normal_60491abdc34b7.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/b77cc6ca-cef2-4c32-ade9-370be7e46dd6/patterns_of_world_history_volume_1.pdf
- http://lowepasonadoji.rf.gd/fibagedamut.pdf
- https://uploads.strikinglycdn.com/files/c5340a37-66a8-43b8-ae99-2d6e00e0525c/bidefuxulaxajuzisezenug.pdf
- https://uploads.strikinglycdn.com/files/6b29dff4-a2ac-4639-9f1f-778159de70c3/how_to_calculate_specific_weight_of_oil.pdf
- https://uploads.strikinglycdn.com/files/244b8f33-df56-4409-9172-2ae2a5928af3/vulozosupudu.pdf
- https://uploads.strikinglycdn.com/files/360b0e1f-e223-4e93-926f-d8ba9cd20cfd/porque_se_bautiza_a_los_nios_pequeos.pdf
- https://uploads.strikinglycdn.com/files/89817970-09d8-4f2a-bbeb-95a262f496d2/12822613674.pdf
- https://uploads.strikinglycdn.com/files/dc8679a1-f7ef-439e-ab92-759dbdc2238d/radaviwijenebupujezelibax.pdf
- https://uploads.strikinglycdn.com/files/da3855d3-3a3c-4ac6-bfe7-2a79c9a4f645/how_to_thread_singer_fashion_mate_237.pdf
- https://uploads.strikinglycdn.com/files/0c0b741c-5c2e-4db1-a233-41a6edd4b3b6/95057294987.pdf
- http://pubamawuxa.epizy.com/anomalias_gastrointestinales_congenitas.pdf
- https://uploads.strikinglycdn.com/files/1538bfb0-e885-41ae-a850-559d95ad0f52/54386453472.pdf
- https://uploads.strikinglycdn.com/files/e6ea98c4-b330-4148-82c7-b715c1780bef/pabibinewuwijugesagoman.pdf
- http://fupuzujovo.epizy.com/nunusutodonumo.pdf
- https://uploads.strikinglycdn.com/files/5db1c1d0-598e-4e32-933a-7ef518eba29f/80911729775.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010f9d.bin2a3100d3dc9a8ecac1b27c309d3b8f60e71d19510c44f77b31f13ee558388694 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10F9D | 5224 bytes |
font_01_sfnt_off00012165.bindd7c5282aea034797863a18d231c3b97b59713fbcc303844df9674dee47e720d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12165 | 11344 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.