MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. The document body, though heavily obfuscated, combined with the 'SE_ADVANCE_FEE_SCAM_LURE' heuristic, indicates a phishing attempt related to advance-fee fraud. The embedded URI 'https://vilenefex.ru/wix?keyword=a+poison+tree+by+william+blake+worksheet' is the primary indicator of a malicious external resource.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/wix?keyword=a+poison+tree+by+william+blake+worksheet
- https://jatilupek.weebly.com/uploads/1/3/4/4/134491857/vipagabe.pdf
- http://tobufupevujuma.mygamesonline.org/pierre_crepon_evangelios_apocrifos.pdf
- https://dikemogegopur.weebly.com/uploads/1/3/1/4/131406608/wolubafowivumowa.pdf
- https://fosobezi.weebly.com/uploads/1/3/4/8/134898374/196bc06540b8e.pdf
- https://fiziragib.weebly.com/uploads/1/3/4/3/134345091/gaxegeboxoge_kuradorubanom_gujesoxiwuv_tepefe.pdf
- http://kapovulup.mywebcommunity.org/langston_hughes_high_school_atlanta.pdf
- http://vivekawiga.sportsontheweb.net/plantronics_c054_pairing_to_base.pdf
- http://xuzobinemipivor.mygamesonline.org/48287611066.pdf
- http://zujejilolo.scienceontheweb.net/34741094343.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/jusagi/49725109603.pdf
- http://mekasesajiw.onlinewebshop.net/aptitude_test_questions_and_answers_of_tcs.pdf
- https://uploads.strikinglycdn.com/files/bd3378ba-2291-4b1f-b4d0-7297b2f7eb2a/vususinexisosovosuxeso.pdf
- https://s3.amazonaws.com/kewuxejikiwe/powermax_turbo_reviews.pdf
- http://nixomirorubu.myartsonline.com/dosemuxifa.pdf
- https://s3.amazonaws.com/dumupa/difference_between_p_type_and_n_type_semiconductor_class_12.pdf
- https://s3.amazonaws.com/vigevot/45040464124.pdf
- https://uploads.strikinglycdn.com/files/fce7d95b-a1c5-476f-b71d-85a2068c1a8f/silumez.pdf
- https://s3.amazonaws.com/purixifusipelid/61112203761.pdf
- https://uploads.strikinglycdn.com/files/e36e40d6-ba72-4f08-bccc-72d4ecead024/28130368061.pdf
- https://uploads.strikinglycdn.com/files/7857304d-4fbc-40b4-ad69-6507a93808ef/which_parent_functions_have_an_asymptote_at_y__0.pdf
- https://s3.amazonaws.com/tozaduliwubega/tennis_elbow_manager_2_guide.pdf
- https://s3.amazonaws.com/kelukakeb/el_material_seth_jane_roberts.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010675.bin5c1c49ce3deed9b19821b58dcfd8a1eded7d0de1b797c45c163e4244d37ca7df |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10675 | 5444 bytes |
font_01_sfnt_off000118de.bin5758c5220aa494767d4f75100a7f8a38bc67181350d88561545d8ed5fd60d9f2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x118DE | 11648 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.