MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The document body, though partially garbled, suggests a lure related to 'Descubre 2 workbook answers page 28', likely to trick users into clicking the embedded malicious URL. The presence of an external URI heuristic further supports the phishing attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/wix?keyword=descubre+2+workbook+answers+page+28
- https://cdn.sqhk.co/ruwonumatag/jbiggip/14394123022.pdf
- https://cdn.sqhk.co/dikizumi/mJjc6xS/notapawewududoziz.pdf
- https://cdn.sqhk.co/mevojazix/dia58R6/dapanojakon.pdf
- https://static.s123-cdn-static.com/uploads/4445324/normal_5fffbf639fce4.pdf
- https://static.s123-cdn-static.com/uploads/4488100/normal_5fd08566bb2df.pdf
- https://cdn-cms.f-static.net/uploads/4417141/normal_6054aa5bebf23.pdf
- http://wewazer.iblogger.org/lobobamegexirufiniku.pdf
- https://cdn.sqhk.co/favosejo/fW8ZAK6/instagram_downloader_shortcut_2020.pdf
- http://fontawesome.iohttp://fontawesome.io/license/
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://16b16ea1-1eac-4681-bfdb-39d0b7b0c60a.filesusr.com/ugd/d6b497_e5ba4f2772254e58883fe2bfa72765fb.pdf?index=true
- https://uploads.strikinglycdn.com/files/c929c9e9-b2bd-4eaa-8117-3512b908789c/38062904951.pdf
- https://uploads.strikinglycdn.com/files/db80a856-ee72-4004-b6aa-1619ce938a47/what_is_the_importance_of_a_college_education_essay.pdf
- http://xuvemotoguno.epizy.com/ipad_mini_5_front_camera_not_working.pdf
- https://a52dd608-e7dd-4d50-8005-e0fd7a3896b4.filesusr.com/ugd/43d2fc_74dd361167c0478cb6591ac4f4716edc.pdf?index=true
- https://uploads.strikinglycdn.com/files/5f100bf3-8397-4f12-bb96-0dcc022f9f3c/osi_7_layer_model_examples.pdf
- http://futifuzofu.rf.gd/54982182591.pdf
- https://uploads.strikinglycdn.com/files/fc46e92b-3037-4cf0-872d-65f42c811258/htc_m8_vs_m9.pdf
- https://e3ba7771-1cf2-49b9-be81-d91832e8ed63.filesusr.com/ugd/bc9675_51e760a6e071446f96fcc799c16bd3fa.pdf?index=true
- https://eee7329a-c4d5-4508-a8fd-a8ba515f7d9f.filesusr.com/ugd/5ed802_436c29c9ddfd46298401c8db6d5dacd2.pdf?index=true
- https://510b81f6-be4e-4e40-9acf-3f60af495837.filesusr.com/ugd/5f226b_49e8a1553567436896d143f7d21daea2.pdf?index=true
- https://uploads.strikinglycdn.com/files/7773cd47-fb18-4d78-97e1-b602c6568c89/how_to_watch_call_me_by_your_name_on_netflix.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00012788.bin1db75d90ae4e5b7cf7dbb76b39ec340aa2af81009f3a905eb2904ee0cf40d43b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12788 | 3408 bytes |
font_01_sfnt_off00013504.bin31719a4e6870b9596c7ce5d728204bf0efa7287cc9e2cdac244862d65d1b6767 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13504 | 96640 bytes |
font_02_sfnt_off000254c7.bin9399a50ca4bd717b0c1e76369a71d4cea94fbb2661088e1cbc9b3c85778508d8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x254C7 | 5688 bytes |
font_03_sfnt_off00026852.bin2f3772a767fccf660e09dbe7132f7c4c367e94b5899b4dba80b2de9f574f7dcc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x26852 | 12048 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.