MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL that redirects to a site offering movie downloads, likely a lure. The presence of a 'download button' heuristic further supports a phishing or social engineering attack pattern.
Machine Learning
- Nyx PDF Classifier malicious score 0.9986
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/123?utm_term=alien+vs+predator+full+movie++300mb
- https://cdn.sqhk.co/litalile/jaighA6/29566995877.pdf
- https://cdn.sqhk.co/rinilafexowi/sifFwhh/coffin_nails_ombre_yellow.pdf
- http://paxezimusosesa.scienceontheweb.net/candlestick_patterns_for_day_trading.pdf
- https://cdn.sqhk.co/luwokiseg/iie8hbE/costumes_for_halloween_male.pdf
- https://cdn.sqhk.co/datimemovuko/hjjbJ1Z/41670991901.pdf
- http://beririka.scienceontheweb.net/how_to_wear_a_surgical_mask_with_pleats.pdf
- https://cdn.sqhk.co/zikufivol/9ojfvPz/98437248430.pdf
- https://cdn.sqhk.co/tuledapozato/bDIajd0/53067254445.pdf
- https://cdn.sqhk.co/wazikunal/bvih7Gz/pirate_art_projects_for_toddlers.pdf
- http://fanisore.sportsontheweb.net/dark_souls_2_design_works_review.pdf
- http://wivevadevenumet.mywebcommunity.org/pathophysiology_textbook_download.pdf
- http://dorugatutaxovi.scienceontheweb.net/nafawobelurepenofogiwi.pdf
- http://tadurarawi.mypressonline.com/berlin_lonely_planet_download.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/e1617057-0fef-4752-ab73-f662c943d787/nespresso_aeroccino_plus.red_light_blinking.pdf
- http://gixopiv.onlinewebshop.net/best_fitbit_versa_lite_watch_faces.pdf
- https://uploads.strikinglycdn.com/files/048e8306-9f1a-4a8a-8efd-0b1b193b85b0/81665973203.pdf
- https://uploads.strikinglycdn.com/files/2b38e105-7694-425b-beb8-eb54b5d9b169/guitar_chords_songs_for_beginners_hindi.pdf
- http://fojakosi.atwebpages.com/among_the_impostors_chapter_1_summary.pdf
- https://uploads.strikinglycdn.com/files/a980b0de-e78a-4b13-be01-b7ddb014ece6/20876747426.pdf
- https://s3.amazonaws.com/lezerawe/dajavarovatavu.pdf
- http://kususen.myartsonline.com/tenewedarenekamopujixade.pdf
- https://s3.amazonaws.com/palikuvexake/gegaberezixuwimiw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://savannah.gnu.org/projects/freefont/
- http://www.gnu.org/licenses/
- http://www.gnu.org/copyleft/gpl.html
- http://scripts.sil.org/OFL
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f299.bin8187145963fbf8e0b7977f93bb9cbfc296fb812f6e2b6f40a3c8d31ca5a797a4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF299 | 6744 bytes |
font_01_sfnt_off00010380.bincafe2c12b83fe133dc49b174405a64f65556d96360f458ac3595c701564df837 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10380 | 5564 bytes |
font_02_sfnt_off0001163f.bin98b93dda20bf2094931b70888c2c7c01e44614be57eead2cbfadfe23c23e1af0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1163F | 1808 bytes |
font_03_sfnt_off00011f28.bin4a1de45d325d3a32ff8ff1a7b4e61c4132f7f819119afc16b5c080f42420575e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11F28 | 11572 bytes |
font_04_sfnt_off000146ca.bince7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x146CA | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.