MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL pointing to 'zajinet.ru', which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, contains references to 'wkhtmltopdf' and a date, suggesting it was generated programmatically to appear as a legitimate document, likely a lure for a software download.
Machine Learning
- Nyx PDF Classifier malicious score 0.9810
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=muslim+pro+mod+apk+revdl
- https://cdn-cms.f-static.net/uploads/4496001/normal_601c7ae18676c.pdf
- https://static.s123-cdn-static.com/uploads/4387040/normal_5feb4e442c91c.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.opentle.org
- https://uploads.strikinglycdn.com/files/3591a312-f2cd-49e0-9931-c89256f8055c/buffalo_wild_wings_nutrition_guide.pdf
- https://uploads.strikinglycdn.com/files/4facd827-d2bc-4893-8a68-9cbc89308f27/74466550824.pdf
- https://uploads.strikinglycdn.com/files/04041a6f-3a69-4158-995b-facb8c2adeea/xabakeguxixo.pdf
- https://uploads.strikinglycdn.com/files/393ba88e-af08-4333-a7a4-396423c54ffc/ruwefimixusafebiguxonunu.pdf
- https://uploads.strikinglycdn.com/files/42cd5a00-0009-4056-890c-48d71c861310/flowermate_v5.0_review.pdf
- https://s3.amazonaws.com/poresi/58367830653.pdf
- https://s3.amazonaws.com/bufipevuril/bow_wow_ft_ciara_like_you.pdf
- https://uploads.strikinglycdn.com/files/758466b1-6bda-46d9-9956-f023ee0fe148/what_does_wheat_belly_mean.pdf
- https://s3.amazonaws.com/vebisop/66612755745.pdf
- https://s3.amazonaws.com/lanaladu/71527991534.pdf
- https://uploads.strikinglycdn.com/files/b5e4b238-d5f7-4dbe-a74a-761462509924/sezafawixebomos.pdf
- https://s3.amazonaws.com/wivunonovef/how_to_work_a_ninja_professional_blender.pdf
- https://uploads.strikinglycdn.com/files/4f31f6df-793f-4247-a41d-d05dd40daaad/what_are_the_traditional_chinese_musical_instruments.pdf
- https://uploads.strikinglycdn.com/files/a921137e-910f-4b15-94e5-e32422e16cd7/34672946389.pdf
- https://s3.amazonaws.com/mamibis/converse_one_star_platform_sandal.pdf
- https://uploads.strikinglycdn.com/files/443409e3-5501-4f59-98b5-2d36200217bb/tapijugojolapax.pdf
- https://uploads.strikinglycdn.com/files/671b4a4f-49e2-4b85-9379-0706adec6da2/damagusalawidevarewolu.pdf
- https://s3.amazonaws.com/xoguwavosuje/scary_movie_3_parents_guide.pdf
- https://uploads.strikinglycdn.com/files/7e7020b5-136c-4cdf-8c1e-b5695539ff96/starbucks_coffee_menu_philippines.pdf
- https://uploads.strikinglycdn.com/files/07d437e2-5c7f-4e94-82b6-01627c0c6b81/mumobosibob.pdf
- https://s3.amazonaws.com/dudujopixejikug/behringer_x2222usb_mixer.pdf
- https://s3.amazonaws.com/xakusineba/26935276363.pdf
- https://uploads.strikinglycdn.com/files/f9edd4cb-19e8-48a3-bdca-da53e00aefb6/87855661114.pdf
- https://uploads.strikinglycdn.com/files/63e46141-e4ad-4a43-a8c2-261fa00e62ca/the_wounds_never_heal_quotes.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
- http://scripts.sil.org/OFL
- http://www.gnu.org/licenses/gpl.html
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_007_off00015fa1.bin76a7258249b886fbe78bf60ad2be1345b2dfebb69ed4f559690dfc5b27a2b5cf |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x15FA1 | 28080 bytes |
font_00_sfnt_off00010521.bin257a24f35322654a0ac3b1ace3f568d77af94818aa5551b651089357d14f6b05 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10521 | 4132 bytes |
font_01_sfnt_off000113c2.bin413aa37a29ef230edd101639aade952c72e21b5666a0a13aba73822a1986c969 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x113C2 | 5232 bytes |
font_02_sfnt_off0001257c.bin538512be6c526ea957b587fa229624d829dca4873b622d187784a60d2c877fcd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1257C | 6640 bytes |
font_03_sfnt_off0001371a.bin71b99ae9be385bc137d2c6c672367fa7579d0d159e606e3f9b4bd48475d8c4e6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1371A | 12680 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.