MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, vilenefex.ru, which is likely part of the attack chain. The document body, though heavily obfuscated, suggests a lure related to an 'Adobe photoshop tutorial in tamil pdf', aiming to trick users into downloading a payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/award?keyword=adobe+photoshop+7.+0+tutorial+in+tamil+pdf
- http://vemolizikogevu.22web.org/52158742662.pdf
- https://cdn.sqhk.co/naxusepimosa/iQyhcji/used_car_price_calculator_saudi_arabia.pdf
- http://microbladingeyebrowsdallastx.com/vabejesarebepabivomfsi3f.pdf
- https://static.s123-cdn-static.com/uploads/4456399/normal_5ff8da4bc2493.pdf
- http://momijorifuwuve.22web.org/55516257053.pdf
- https://cdn-cms.f-static.net/uploads/4474978/normal_60110ba9b9745.pdf
- https://cdn-cms.f-static.net/uploads/4463807/normal_60306dc7ee8b0.pdf
- https://cdn.sqhk.co/jimatoju/Chijbig/15491136702.pdf
- https://cdn.sqhk.co/wosipuvetot/oijibv9/nuranofodaxosometona.pdf
- http://edayafar.xyz/nakagosinatosaliloxupupern825.pdf
- http://vekvelo.ru/mutarimhj8q.pdf
- http://muritolovaj.iblogger.org/lcm_hcf_full_form.pdf
- https://cdn.sqhk.co/makafabakuna/iicSPZY/95810070181.pdf
- https://cdn.sqhk.co/xuteposidobi/cjckhbF/ant_smasher_old_version_apk.pdf
- http://boothattendant.com/10068635056q5uoe.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://b133b025-67d1-4190-9e53-fbb99503dec2.filesusr.com/ugd/caf13f_416fc8b2f9ff4482bc7b4e4feea41ad6.pdf?index=true
- https://83f018a0-8e49-44f0-b57e-805e464a5f06.filesusr.com/ugd/10a4aa_be42977bf05c475ebf3db4c2de6ab730.pdf?index=true
- https://a2214900-82f6-4ed5-a432-d5ffd14110fa.filesusr.com/ugd/306b6b_6e5972f12b0944978876b8a69e1df3ef.pdf?index=true
- http://sovezogodum.rf.gd/mv_bts_love_yourself_answer_epiphany.pdf
- https://e301b21f-f707-426c-a094-6199d4b1a2d6.filesusr.com/ugd/f65518_65beab8d49834b5a8f265c9efa6efb97.pdf?index=true
- https://3682d434-6e27-4ac8-9ac2-d3ec24fa429c.filesusr.com/ugd/9b5f63_3fbb7a8c48074c95a196dba6676b76c1.pdf?index=true
- https://4a31e3f8-49e3-4331-b1a9-c0bb7a6b9dbc.filesusr.com/ugd/599f1c_578b96a71b96466c822afd8a10e6ce40.pdf?index=true
- https://e22e8d81-f41f-4d51-abb1-39b19d2d32bb.filesusr.com/ugd/96bf9d_ba0fc27f89034f22a6efe0d3a5e05304.pdf?index=true
- http://gumijodopivu.rf.gd/bleeping_computer_s_adwcleaner.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fd80.bin898e3a7998758f412466b5db2d3f3bbef97bc6d6489b518a8823f71d5f209f45 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFD80 | 5664 bytes |
font_01_sfnt_off000110a0.bin75472eadb41fed883ff34aec087627c24ebaaae37be05e7cea3cd9d80c0d5e6d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x110A0 | 11288 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.