MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document identified as malicious by ML classifiers and ClamAV. It contains an embedded URI pointing to a suspicious domain, likely intended to host a malicious payload or phishing content. The document body, though heavily obfuscated, suggests a lure related to 'Virgilio bucoliche'. No scripts were extracted, but the presence of an external URI is a strong indicator of malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/123?utm_term=virgilio+bucoliche+pdf
- https://cdn-cms.f-static.net/uploads/4417808/normal_6040e9b71aa4f.pdf
- http://peteferix.mypressonline.com/89326681569.pdf
- https://cdn-cms.f-static.net/uploads/4489259/normal_5fd7f8e218e3f.pdf
- http://nosilekexiwot.mywebcommunity.org/rozem.pdf
- http://vijuziruzunubiz.iblogger.org/pevikixujasivoxo.pdf
- http://zobebukore.22web.org/likuziwixalakupubademor.pdf
- http://xarubuxa.iblogger.org/walezanomirezava.pdf
- https://static.s123-cdn-static.com/uploads/4450046/normal_5ffd464985c76.pdf
- http://wemuwetafivaxe.sportsontheweb.net/65556906770.pdf
- http://posebakuxosafod.getenjoyment.net/90899954838.pdf
- http://duzegipim.22web.org/kisalibelikokesuwi.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://gaxunexuxulaxed.epizy.com/risugek.pdf
- http://kinosunun.epizy.com/85682475918.pdf
- https://s3.amazonaws.com/patilawasu/cards_against_humanity_expansion.pdf
- https://uploads.strikinglycdn.com/files/7f6c507e-26d4-4bab-b8e3-31c3a657fe87/6126540978.pdf
- https://s3.amazonaws.com/xomudufe/35745005936.pdf
- http://difedomuki.epizy.com/48836064129.pdf
- http://ravesezubepad.epizy.com/jumod.pdf
- https://uploads.strikinglycdn.com/files/b9afc2a4-97e5-42c2-a69d-611aabfd5bf0/62211469327.pdf
- https://s3.amazonaws.com/luxaduzimase/best_shooting_games_for_android_under_100mb.pdf
- http://popofisofol.myartsonline.com/nosezofepexokamakurir.pdf
- https://uploads.strikinglycdn.com/files/39cda619-32d2-48e0-a685-d138fef3fbf2/salary_of_a_medical_lab_technician_in_kenya.pdf
- http://nafakosoleg.epizy.com/14996831563.pdf
- https://s3.amazonaws.com/tiluwisulepam/street_map_bruges.pdf
- http://vuwofaxanubus.epizy.com/the_standard_dental_insurance_login.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000123dc.bin7619ba56c576f01625411ee20fdd0761cf30cb8d88b3921b063c3dc1023cbfe9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x123DC | 5132 bytes |
font_01_sfnt_off00013553.bin53106a6c93e9c67ed7d90034cd6a6f859144102376483c1b6534bdb73bd9091f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13553 | 14400 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.