MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://yafferge.ru/strik?utm_term=iksar+hide+cape+p99'. This indicates the document's primary purpose is to lure users to this malicious URL. The ML classifier also strongly flagged this PDF as malicious, supporting the assessment of a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9921
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://yafferge.ru/strik?utm_term=iksar+hide+cape+p99 In PDF document text
- https://static.s123-cdn-static.com/uploads/4408475/normal_5ffdcbf4457cb.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4454041/normal_5ffe241b58c8d.pdfIn PDF document text
- http://petersikdar.com/cdma_full_form_in_managementy61en.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4470223/normal_5fccebe82cc77.pdfIn PDF document text
- http://najefot.22web.org/bangladesh_railway_job_form_2019.pdfIn PDF document text
- http://italdom.fun/76839433651udk0f.pdfIn PDF document text
- https://penotogales.weebly.com/uploads/1/3/1/4/131438478/zidepunavojeluna.pdfIn PDF document text
- http://trynutra.shop/all_future_tenses_exercises_with_answers0a4dz.pdfIn PDF document text
- http://good-production17.site/hyundai_creta_featuresw16nd.pdfIn PDF document text
- https://gojatoxemoniro.weebly.com/uploads/1/3/4/8/134894745/xawajodupamiwu.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4388629/normal_6021e81d5f8ac.pdfIn PDF document text
- https://mopomavimixefor.weebly.com/uploads/1/3/1/1/131164117/zakagubivul_xaribuvor_mofinimutegono.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/suzixegazunow/the_sims_4_turbo_careers_lots.pdfIn PDF document text
- http://fozabenisos.epizy.com/beyond_band_songs.pdfIn PDF document text
- https://s3.amazonaws.com/sabobenuwe/6743253382.pdfIn PDF document text
- https://s3.amazonaws.com/waxapoz/2864943021.pdfIn PDF document text
- https://s3.amazonaws.com/dadupawo/vifimixupa.pdfIn PDF document text
- http://wotisonuli.epizy.com/hiv_antiretroviral_guidelines.pdfIn PDF document text
- https://s3.amazonaws.com/gazitif/lapazibemolubegolep.pdfIn PDF document text
- http://gevewodex.epizy.com/dudozukagamegej.pdfIn PDF document text
- https://s3.amazonaws.com/piradi/upload_speed_meaning.pdfIn PDF document text
- https://s3.amazonaws.com/jitimesolagun/sample_of_works_cited_page_apa_format.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000339eb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x339EB | 2888 bytes |
SHA-256: ba2356565adfbad3bce05071f499e58eec20abd0a5d273d6699ec2874c27599c |
|||
font_01_sfnt_off0003442e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3442E | 5284 bytes |
SHA-256: f2989ec5987b3050ca9af14ca0467a5f5f4a5b443fe7ef55313b08b5ee7568cb |
|||
font_02_sfnt_off00035620.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x35620 | 11692 bytes |
SHA-256: fe2476ed98581e1ce08bb93282252e0f1d4a9ee88d2ff47009bc3b1ab17d8c8a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.