MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains an embedded URI pointing to a suspicious domain, likely intended to trick the user into downloading a malicious payload or visiting a phishing site. The document body, though heavily obfuscated, suggests a lure related to educational content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/award?keyword=elementary+algebra+questions+and+answers+pdf
- https://cdn-cms.f-static.net/uploads/4375703/normal_5fd9647cc6642.pdf
- https://cdn.sqhk.co/sebutarukaw/gd3vggW/top_100_coolest_cars_in_the_world.pdf
- https://static.s123-cdn-static.com/uploads/4419191/normal_5ff8c7a268088.pdf
- https://cdn.sqhk.co/belebudetub/PjaDCgg/world_war_1_timeline_activity.pdf
- http://trokot-tonirovka.online/86971630599qxh6d.pdf
- https://cdn.sqhk.co/nakunadubux/jsihw8E/99919614087.pdf
- http://s7hmus.org/nalurugujixegeltu5pe.pdf
- https://cdn.sqhk.co/letinumi/va4gdlH/funny_racing_memes.pdf
- http://virnet77.ru/standoff_2_apk_mod_money_0._10._11x4ll2.pdf
- https://cdn-cms.f-static.net/uploads/4424025/normal_60174e273ba9d.pdf
- http://lnstgramhelpcopyright.com/84181329262kfqix.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/04180513-973d-48be-8333-3eef8ad4a890/how_to_disengage_hydrostatic_transmission_john_deere_zero_turn.pdf
- https://uploads.strikinglycdn.com/files/dba54faa-81f6-43f2-b55f-004f300658e8/the_green_mile_book_chapter_summaries.pdf
- https://ac3db616-04cb-40f1-8357-c67041f5e20c.filesusr.com/ugd/eda9ba_40fca80680ac4d8a8df6df3d870ac0aa.pdf?index=true
- https://50aad03f-9d2a-47e6-be13-abd12f321b17.filesusr.com/ugd/3fd638_5f418aa4d0ce4a70970ed1ca373ae565.pdf?index=true
- https://2f8a6ab9-e864-4757-b083-6627a13f4c48.filesusr.com/ugd/405339_96ab5b4db99a451ebb2c6b8072fbc371.pdf?index=true
- https://uploads.strikinglycdn.com/files/98826f10-867b-41cc-ae75-79a437e5c4e1/74077358818.pdf
- https://uploads.strikinglycdn.com/files/fe896e7a-a3f6-49a9-bd44-6130a0f7c85b/rizubiruzulara.pdf
- http://bavidoripo.epizy.com/english_for_aviation_oxford.pdf
- http://jufowepazo.rf.gd/208242124.pdf
- https://uploads.strikinglycdn.com/files/58850a21-11ec-42fd-8375-c15be2266dba/storyboard_template.pdf
- http://kavaxix.rf.gd/deworubajaretewuwawep.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f201.bin613069afeda1a896ba0167e6399b587afd740c1e1743cc9c78e4ae8dd95c7282 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF201 | 5660 bytes |
font_01_sfnt_off0001052e.binc841eeac90a0da90bc20edf4f401b6a3f245ed4ddc9658e14e234c9d4681566c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1052E | 10932 bytes |
font_02_sfnt_off00012a51.binb50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12A51 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.