MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ML classifiers and ClamAV, specifically as a phishing trojan. It contains an embedded URI pointing to 'ponafet.ru', which is likely a malicious domain used to host phishing content or distribute further malware. The document body, though heavily obfuscated, contains keywords related to 'back to school' and 'pdf', suggesting a lure for users. No scripts were extracted, but the PDF structure and embedded URI strongly indicate a phishing or malware delivery attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9967
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/award?keyword=back+to+school+get+to+know+you+activities+pdf
- http://sukutoxuwurif.mywebcommunity.org/14697417421.pdf
- http://fupemagis.mywebcommunity.org/causas_sociales_del_alcoholismo.pdf
- http://jafoxidulez.mypressonline.com/givete.pdf
- http://xuzotudaraderuf.mypressonline.com/debate_formats.pdf
- http://forisawidokomor.sportsontheweb.net/champs_behavior_chart.pdf
- http://fulokixowo.scienceontheweb.net/accounting_and_financial_statement_analysis.pdf
- http://roselosudeve.sportsontheweb.net/81821780376.pdf
- http://maroxelil.22web.org/rulewotemesomit.pdf
- http://bamefidev.mygamesonline.org/87967613334.pdf
- http://bepibolet.22web.org/hostplus_superannuation_form_for_employer.pdf
- http://zatutajijiti.getenjoyment.net/77095065656.pdf
- http://sugalomiwuto.getenjoyment.net/95344611493.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/195e7990-62fc-4c4b-b6fe-4edec8712573/34420869785.pdf
- http://rojanesifilagu.myartsonline.com/44500266970.pdf
- https://s3.amazonaws.com/kakef/sifinimosurapukivav.pdf
- http://rijonitapadon.myartsonline.com/ageless_body_timeless_mind_full_free_download.pdf
- https://uploads.strikinglycdn.com/files/257c0b0e-6e2e-4f3b-b41a-53c073dfa030/stannah_stairlift_model_600_codes.pdf
- https://uploads.strikinglycdn.com/files/103ead43-16aa-46f1-bc9f-6345fec43f4a/asus_rt-n66u_wireless_speed.pdf
- http://wawikoduvebakap.onlinewebshop.net/cardiovascular_physiology_questions.pdf
- https://s3.amazonaws.com/jixeremipet/485353645.pdf
- http://gudenojotu.epizy.com/perodadujiwemuxi.pdf
- http://xazoviwupudowol.rf.gd/dolce_gusto_delonghi_manual.pdf
- https://uploads.strikinglycdn.com/files/93349e18-4b79-4720-ad54-0c26ce0afb12/finnegans_wake_restaurant.pdf
- https://uploads.strikinglycdn.com/files/a7f882db-032f-49b8-8736-6a834b9d79cf/89951820259.pdf
- https://s3.amazonaws.com/zoromexemuzid/vcruntime140d._dll_32_bit.pdf
- http://zenakezogutomu.onlinewebshop.net/kujabiwabupewu.pdf
- https://s3.amazonaws.com/suzujewa/cat_and_gate_full_form.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001116f.bine9a28989cfc77b85d1ede18a300b5ad5f80a6cdd9c57a0fcce2cab9b02c4aa82 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1116F | 5688 bytes |
font_01_sfnt_off000124fc.bindd130c99b89ab0a08ae0e4ddff1eb78aba8416b841cbf99e871bd20d9b69f649 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x124FC | 10196 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.