MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document that contains embedded URLs, one of which is flagged as malicious. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or delivering a secondary payload. The document body, though heavily obfuscated, appears to be a lure related to management control systems, aiming to trick users into clicking the malicious link.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/award?keyword=characteristics+of+management+control+system+pdf
- http://bawikivogo.22web.org/10757318359.pdf
- http://sebekeruxa.iblogger.org/play_chess_online_with_friends_android.pdf
- http://usesalon.xyz/aeron_chair_headrest_atlasi29ph.pdf
- http://spoonnumberone.xyz/kalakekanolagabivudjr2b5.pdf
- http://erogan-columbia.site/salary_for_entry_level_information_technologyzkaci.pdf
- http://memokepudag.iblogger.org/blank_australia_map.pdf
- http://newsportstechnology.ru/60987501925olm10.pdf
- http://zemimumaloger.iblogger.org/fizemawakudajub.pdf
- http://koteyarn.moscow/novinipakezibuk1ed7.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/lepefi/besimitije.pdf
- http://rukateridexak.rf.gd/fishing_report_cape_cod_times.pdf
- http://tobekiginekafo.epizy.com/99367629764.pdf
- https://cc652f91-b1ab-470c-b36f-46d838ef85b2.filesusr.com/ugd/fbccce_b7a337a194e04116b60ec66c39332869.pdf?index=true
- http://bumusilofinufaf.rf.gd/32297413569.pdf
- https://eadb47d6-6712-4ecd-aa5a-2cdcf2d90b86.filesusr.com/ugd/c844bf_f407effaa532441cb627310403f42a42.pdf?index=true
- http://febarufowit.epizy.com/ripum.pdf
- https://s3.amazonaws.com/mikibetiv/vomakabawadefa.pdf
- https://0c3b2bb2-3ac9-4e0e-a0b2-530a831cdf0d.filesusr.com/ugd/23193f_85e4a364ee6e4ce496081067502d7cb4.pdf?index=true
- http://zowiseli.epizy.com/blackberry_z3_software_update.pdf
- https://s3.amazonaws.com/paxuvagal/internetworking_with_tcp_ip_principles_protocols_and_architecture_6th_edition.pdf
- https://s3.amazonaws.com/palikuvexake/oster_convection_countertop_oven_parts.pdf
- http://koziviwuvep.epizy.com/77248882214.pdf
- https://1a441fb4-51dd-4528-a053-eb59ff664e18.filesusr.com/ugd/43d9d5_2fde436b4f60421caadfc5a4a729289a.pdf?index=true
- https://01d7ec8a-e38e-4e33-8c76-1be31754498b.filesusr.com/ugd/24d943_f11e4ada2da9414ca330b224bdaa845b.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eba9.bina04361d8ff8da6fb649a02287b3ad0b40c7c30d447fad4737d730e536a45a983 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEBA9 | 5576 bytes |
font_01_sfnt_off0000fe79.bin8eef06bf0d0ceb6eb4ede09487267eaf89d6cde9d3b41b20273c9c280103c84d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE79 | 10088 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.