MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF containing embedded URLs that point to suspicious domains, suggesting it's part of a phishing or malware distribution scheme. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a lure to download further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/wix?keyword=when+you+reach+me+pdf+free+download
- https://nenejafaf.weebly.com/uploads/1/3/5/3/135393494/4fc3f18f0.pdf
- https://dasezakam.weebly.com/uploads/1/3/4/8/134883145/cdf689f9.pdf
- https://jejegufixi.weebly.com/uploads/1/3/2/7/132740716/numakapebivamav.pdf
- https://cdn.sqhk.co/letijefa/igLihRd/melerafe.pdf
- https://static.s123-cdn-static.com/uploads/4530151/normal_5fdf703c88083.pdf
- https://cdn.sqhk.co/jagibuvat/jbkijkm/835559867.pdf
- https://wesaxewotivaf.weebly.com/uploads/1/3/4/5/134578523/35b54962.pdf
- https://zifofuxe.weebly.com/uploads/1/3/5/3/135386801/pamit.pdf
- http://zakosemej.mypressonline.com/davigij.pdf
- https://romevezijije.weebly.com/uploads/1/3/4/7/134756673/5aa9d.pdf
- https://cdn.sqhk.co/tezofugowura/idhjDhc/madizoterozubilon.pdf
- https://cdn-cms.f-static.net/uploads/4366014/normal_5fe8f4a72fa3f.pdf
- https://static.s123-cdn-static.com/uploads/4389352/normal_5fee1d92c31b2.pdf
- https://pezimanazeto.weebly.com/uploads/1/3/5/3/135309923/7f92c5428d.pdf
- https://static.s123-cdn-static.com/uploads/4471082/normal_5fc8b422d2c59.pdf
- https://wedodoto.weebly.com/uploads/1/3/5/9/135993452/fawuvixubiroz.pdf
- https://nupigefaxobabu.weebly.com/uploads/1/3/1/0/131070289/6120096.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/83401f69-c933-4b06-bbb5-0b622e1e9e26/what_is_atomic_mass_in_physics.pdf
- http://wotidupodugi.myartsonline.com/jon_duckett_html_and_css.pdf
- http://nivuzujanux.myartsonline.com/gopirodibegupobilituwekir.pdf
- https://uploads.strikinglycdn.com/files/d3578fe1-3169-451e-a65c-cc3c6b353491/mastering_data_structures__algorithms_using_c_and_c_free_coupon.pdf
- https://uploads.strikinglycdn.com/files/b7fd253e-b16d-485e-859e-89104533178f/46501189072.pdf
- https://uploads.strikinglycdn.com/files/a60347a7-cfec-4cb1-9cd6-4563d6196bc3/denon_avr_3313ci.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e2df.bin152e6659899b724110b5d9daac929b04d0075a651a62f0e06282541caf356035 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE2DF | 5424 bytes |
font_01_sfnt_off0000f547.bin5b743d6226bbbe5e189fc95fa896aa2463f52887bb5d7f8990a88657ead4bd0e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF547 | 11044 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.