MALICIOUS
116
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file is a PDF document flagged by multiple heuristics and a machine learning classifier as malicious, specifically identified as a phishing or trojan. The presence of a callback lure heuristic indicates the document's intent to trick the user into contacting a fraudulent entity, likely for financial scams or credential harvesting. The embedded URL points to a suspicious domain, further supporting the phishing pretext.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/wix?keyword=sat+crash+course+math
- https://static.s123-cdn-static.com/uploads/4385214/normal_60076dc77d645.pdf
- https://cdn-cms.f-static.net/uploads/4412887/normal_6048c90d97af3.pdf
- https://cdn-cms.f-static.net/uploads/4388413/normal_605558f78b9e0.pdf
- https://cdn-cms.f-static.net/uploads/4383334/normal_604ae6945abd3.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/7d63a769-41a1-4b14-b00a-da0fc688da25/noco_genius_g3500uk_6v_and_12v_3.5_amp_smart_battery_charger.pdf
- https://uploads.strikinglycdn.com/files/f786e742-ec9c-45a6-899a-be3c29572772/93124916491.pdf
- https://uploads.strikinglycdn.com/files/a4d624ce-d562-452d-a519-4b0ef7741246/collins_the_language_of_god.pdf
- https://s3.amazonaws.com/lukepepe/how_to_read_music_score_sheet.pdf
- https://s3.amazonaws.com/gixawetopoli/29297992100.pdf
- https://uploads.strikinglycdn.com/files/de34ce35-4e2f-453b-9099-e55700bb4042/meronigepazukozakubokeki.pdf
- https://uploads.strikinglycdn.com/files/264eb88d-c6ef-449b-9663-cb4987f9ec87/the_magicians_season_2_episode_6_review.pdf
- https://s3.amazonaws.com/fexuror/aprender_japones_basico.pdf
- https://uploads.strikinglycdn.com/files/e82e3751-9c43-4922-92c2-7b4c09f7884b/dufuvosojedixesepugapimis.pdf
- http://piwakolipa.rf.gd/vagadenabezafavolosudipew.pdf
- http://regipikiwubadov.epizy.com/cathode_ray_tube_diagram.pdf
- https://uploads.strikinglycdn.com/files/7f2d2fb0-21f8-4bab-96ed-1bb3cc384f80/farewaratufosofuv.pdf
- https://s3.amazonaws.com/belopudevuzuza/ejemplos_de_limites_infinitos_resueltos.pdf
- https://uploads.strikinglycdn.com/files/ebedead8-fd3c-418a-b9a5-e0c4b511d3eb/nikon_fg_20_manual.pdf
- https://s3.amazonaws.com/titugome/17320504330.pdf
- http://fezokokedi.epizy.com/shadowrun_hong_kong_best_weapon_type.pdf
- https://s3.amazonaws.com/nupotukig/21179676555.pdf
- https://s3.amazonaws.com/tuxutedi/jobuxup.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00015449.binae7db9b3cd35be3a40917dc36f53add4f682021d32cfe803f3cec776805ea39a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15449 | 5112 bytes |
font_01_sfnt_off0001657d.bin596009033c526239a835440774f9da94e297aa216f6ef16eee2775dab8ecd195 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1657D | 11784 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.