MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9989
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/strik?utm_term=the+legend+of+zelda+a+link+to+the+past+free+online+game PDF link annotation
- https://cdn-cms.f-static.net/uploads/4411481/normal_6034c9adae7d2.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369802/normal_60625d55a3fa9.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4413242/normal_60287cb7a1318.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4422908/normal_6069f5d030bb3.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4474170/normal_6059eb4d72cd4.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://s3.amazonaws.com/dudujopixejikug/aua_guidelines_haematuria.pdfIn PDF document text
- https://s3.amazonaws.com/topipovikapari/24956796702.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6cd08f35-9458-4d12-99a9-10b1985b046e/jomokofe.pdfIn PDF document text
- https://s3.amazonaws.com/paxuvagal/badri_songs_naa.pdfIn PDF document text
- https://s3.amazonaws.com/nelizenejakarug/damimi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c840f243-ba84-4323-97da-c6cd90ad451a/the_rockefeller_playbook_download.pdfIn PDF document text
- https://s3.amazonaws.com/litunux/toviwuradivozibut.pdfIn PDF document text
- https://s3.amazonaws.com/wiwamoxamo/38801500882.pdfIn PDF document text
- https://s3.amazonaws.com/zuguvoxoki/bollinger_bands_indicator_mt4.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/22911a2b-7542-4174-a379-d9ef62ec5681/pexasofuz.pdfIn PDF document text
- https://s3.amazonaws.com/zuxime/wilderness_survival_guide_dd.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2694e187-9eee-4df6-8d3c-bf893961ecc0/kisozorod.pdfIn PDF document text
- https://s3.amazonaws.com/risisipajole/desh_bhakti_bhojpuri_video_song.pdfIn PDF document text
- https://s3.amazonaws.com/zuwosil/zygote_android_virus.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d6776aa4-ba6e-45c0-a883-bfcaf6ee8b33/advanced_dungeons_and_dragons_2nd_edition_players_handbook.pdfIn PDF document text
- https://s3.amazonaws.com/batiku/intervening_phrases_worksheet_grade_5.pdfIn PDF document text
- https://s3.amazonaws.com/vutame/78047077724.pdfIn PDF document text
- https://s3.amazonaws.com/bidivo/73926081315.pdfIn PDF document text
- https://s3.amazonaws.com/xupovobejanam/chinese_characters_writing_guide.pdfIn PDF document text
- https://s3.amazonaws.com/rubidokezive/adjectives_and_prepositions_worksheets.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000115f0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x115F0 | 5308 bytes |
SHA-256: 72f7b012a665bd21d5e0bdb0518c3418903f9dd0f680f35dbc8bf12fd4b5ab50 |
|||
font_01_sfnt_off000127d5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x127D5 | 11036 bytes |
SHA-256: 3aaff545d7ca9306c9f490ad120dc3b75424874dd59ffd6f7d87f8359c9496b9 |
|||
font_02_sfnt_off00014d6b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14D6B | 4324 bytes |
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.