MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. It contains an embedded URL that leads to a domain associated with phishing, disguised as information about sciatica stretches. No scripts were extracted, but the presence of a malicious PDF and an external URI suggests an attempt to redirect the user to a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://laborke.ru/pbw?utm_term=bob+and+brad+sciatica+stretches PDF link annotation
- https://static.s123-cdn-static.com/uploads/4366325/normal_6000ad13dc558.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4454304/normal_601d831cd54a3.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4374704/normal_5fd0bb955e37d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4444648/normal_60373d9e3f954.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4487187/normal_601ba3f918eec.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4382962/normal_6016c63e961f4.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4482636/normal_6026926c8ab4c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4380228/normal_6049ca841a0a4.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4385214/normal_60152f054ca5f.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://sovafiben.pbworks.com/f/church_visitor_card_template.pdfIn PDF document text
- http://pebenuziwi.pbworks.com/w/file/fetch/144548418/harry_potter_and_the_chamber_of_secrets_book_google_docs.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/28b7e392-ba8f-410a-88a1-05e1a89f50fe/46282534065.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3e7875ce-8d7c-4b35-a6a4-60e65a090809/adobe_premiere_elements_vs_pro_vs_rush.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/77efa077-9fdf-465e-8681-670a4903868b/weight_of_sony_wega_36_tv.pdfIn PDF document text
- http://vakerul.pbworks.com/w/file/fetch/144697671/831624454.pdfIn PDF document text
- http://minuwaxiper.pbworks.com/f/exercice_accord_adjectif_qualificatif_ce2.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/eb7ba29e-6073-465a-b0ef-3b5d01062552/99789253042.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cb9b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCB9B | 5184 bytes |
SHA-256: 37ab5689e852c98117d74816a7f15b97e8043386e1910929bf32ae9f1858a4a7 |
|||
font_01_sfnt_off0000dd32.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDD32 | 10432 bytes |
SHA-256: 95759e6a6df7e43b3240ce3a579b84dee6ae07521e822d8af96291dad97947c4 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.