MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains embedded URLs that likely lead to further malicious content or downloads. The document body, though heavily obfuscated, suggests a lure related to a 'dengue test report'. No scripts were extracted, but the presence of embedded URLs and the overall detection profile strongly suggest a phishing attempt designed to redirect users to malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/16086f69830c77---45440012877.pdf
- https://xn--80adj7cxa.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/a33338c001b72931a572f0430d2e37a8/55669235435.pdf
- https://bistro-8.com/wp-content/plugins/super-forms/uploads/php/files/57abea119a994a521b89ed5f74a91c97/garefizuf.pdf
- http://vegasoft.hr/wp-content/plugins/formcraft/file-upload/server/content/files/1607d4b6369e6e---funanum.pdf
- https://www.letspassdriving.co.uk/wp-content/plugins/super-forms/uploads/php/files/ekr1g35179i4t4kkje9n20k3i7/91357199296.pdf
- https://adbadog.com/wp-content/plugins/super-forms/uploads/php/files/933a5681f0bea2165f7fdb2c6f075c79/43806084469.pdf
- https://auto-rujo.com/images-editor/file/wibukulikakolewizugu.pdf
- https://nicemexico.net/wp-content/plugins/formcraft/file-upload/server/content/files/160910520aea6c---41891973349.pdf
- https://ceilford.org/wp-content/plugins/super-forms/uploads/php/files/3221c5545524a1bff16a0f34708be3bc/zuxuxivom.pdf
- https://diversified-nj.com/wp-content/plugins/super-forms/uploads/php/files/9378b301e509a0cfbb24648bf8e9047f/94659545414.pdf
- https://ltanimalpark.com/wp-content/plugins/super-forms/uploads/php/files/7620e75ccf895dd36c15c517fdcb7a93/sazatokazewurosixuzowe.pdf
- https://beachesbrewing.com/wp-content/plugins/super-forms/uploads/php/files/df50e89a54e3fb5496d756f89cfba9ad/panoxikumeropimilopalozi.pdf
- https://www.hotel-palladium.gr/wp-content/plugins/super-forms/uploads/php/files/tpspr9anqt6844hvmqt10m0dvh/79238841234.pdf
- http://www.majorisinvestimentos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608fc0af80ec2---31745076148.pdf
- https://abugfreemind.com/userfiles/file/75451458693.pdf
- https://feriaesotericadeatocha.com/wp-content/plugins/formcraft/file-upload/server/content/files/16074cbc159fb5---gisetek.pdf
- http://kagoshimakojintaxi.com/userfiles/file/30543043378.pdf
- https://3dreamstudios.com/wp-content/plugins/super-forms/uploads/php/files/4e94e9a49936a852fe5d2e7cf2313641/74580713202.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://feedproxy.google.com/~r/skout/mBVl/~3/6naE_Nh8_CY/uplcv?utm_term=dengue+test+report+non+reactive
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e0b1.bin5b185835b30e501d1af08794e264d59d61f24d290e5703933f1734e20ef85a28 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE0B1 | 5128 bytes |
font_01_sfnt_off0000f247.bin5f647c0a7fb8505beab758e34ba823c7988f205f950ffa1336a02f55aca7bff0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF247 | 11104 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.