MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains an embedded URL that redirects to a website designed to mimic a movie streaming service, likely as a lure for phishing or to host malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as a phishing trojan. While no scripts were directly extracted, the PDF structure and embedded URI heuristics point towards an attempt to redirect users to a potentially harmful external resource.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/wix?keyword=watch+madea+family+reunion+play+online+free+123movies
- https://static.s123-cdn-static.com/uploads/4481402/normal_5ffcc2de1a9b0.pdf
- https://cdn-cms.f-static.net/uploads/4377113/normal_5fd34515d8369.pdf
- https://xegoratan.weebly.com/uploads/1/3/2/7/132712572/9718635.pdf
- https://static.s123-cdn-static.com/uploads/4372723/normal_5ff2103201863.pdf
- https://cdn-cms.f-static.net/uploads/4391317/normal_60582052a31c5.pdf
- https://vinazova.weebly.com/uploads/1/3/2/6/132695356/a75a7d1c4c73.pdf
- https://static.s123-cdn-static.com/uploads/4381988/normal_5fcf5d9d27497.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/d916d079-2ce6-4693-be3d-acc5c3c06d38/how_to_simplify_exponents_algebra_2.pdf
- https://s3.amazonaws.com/bipovoromoj/airtel_money_adder_apk.pdf
- https://uploads.strikinglycdn.com/files/4f912dbf-a441-45c3-8f46-f4576926cd4e/lexile_to_accelerated_reader_conversion_chart.pdf
- https://s3.amazonaws.com/sasufufa/13626446943.pdf
- https://s3.amazonaws.com/tutasujal/black_and_decker_bread_maker_b1650_parts.pdf
- https://s3.amazonaws.com/gateme/autocad_civil_3d_road_design_tutorial.pdf
- https://uploads.strikinglycdn.com/files/1d49566a-1c52-4043-a0e1-b3ab01d12f2b/93794191752.pdf
- https://uploads.strikinglycdn.com/files/e4a86eab-6318-4443-82b9-ad8487387ff8/remington_12_electric_chainsaw_parts.pdf
- https://s3.amazonaws.com/tinezedu/temakamajovabiwidisosuba.pdf
- https://uploads.strikinglycdn.com/files/745ef03e-134b-48e6-a9a7-f72ff706c8cc/sharp_er-a320_error_codes.pdf
- https://s3.amazonaws.com/limepusotanal/dollar_general_paid_holidays_2020.pdf
- https://s3.amazonaws.com/julexekubaj/how_to_make_my_zagg_keyboard_light_up.pdf
- https://s3.amazonaws.com/wefemabeni/bangla_video_album_song.pdf
- https://s3.amazonaws.com/zolerazowubow/home_delivery_meals.pdf
- https://s3.amazonaws.com/fojaxexino/monthly_chore_chart_template.pdf
- https://s3.amazonaws.com/gitipelut/dudezekidividuwusizagu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f333.binc70aaf20ddfd86f762e7a85f3f73f63ecd745f7bd7bf1138962579c25e529597 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF333 | 5916 bytes |
font_01_sfnt_off0001074e.binf46ffbb2e95bc618b714b2ea68ce254df6f83ae16f2f965b562e8fce0e0b0ebd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1074E | 10584 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.