MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious File Execution: User Execution
T1059.007 JavaScript
The file is a PDF that has been flagged by multiple heuristics, including a high-confidence ML classifier and ClamAV, indicating malicious intent. The 'SE_CLICKFIX' heuristic specifically points to a social engineering attack where the document instructs the user to execute a command, likely to bypass macro restrictions and download a secondary payload. The embedded URL is a strong indicator of the download source.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
ClickFix social engineering attack high SE_CLICKFIXDocument instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/strik?utm_term=edit+text+in+paint.net
- https://cdn-cms.f-static.net/uploads/4485930/normal_6048c512cf720.pdf
- https://cdn-cms.f-static.net/uploads/4467322/normal_600e5271097b5.pdf
- https://cdn-cms.f-static.net/uploads/4447912/normal_600fe7795c620.pdf
- https://cdn-cms.f-static.net/uploads/4455660/normal_6056e8c8c6507.pdf
- https://cdn-cms.f-static.net/uploads/4445125/normal_604bbb09908c5.pdf
- https://cdn-cms.f-static.net/uploads/4380082/normal_5fd1d6fc8eb68.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/be19967a-1c43-4fb9-a879-0b7c7d150c1a/how_to_manage_a_team_as_a_team_leader.pdf
- https://s3.amazonaws.com/gewuwasi/riluruzelupovigowi.pdf
- https://uploads.strikinglycdn.com/files/6f01e2b9-695b-4538-b847-a501f6897fdc/30494953699.pdf
- https://uploads.strikinglycdn.com/files/a98c9d86-7564-495e-a60e-2abcdf7486a5/pixma_mp240_driver_download.pdf
- https://uploads.strikinglycdn.com/files/283a75b9-3cd6-4a87-b2f6-d24059ed64cb/68478761534.pdf
- https://uploads.strikinglycdn.com/files/842d38b4-1f4c-4a01-a1c4-d2e13df0dbd1/jovujalojajaziki.pdf
- https://s3.amazonaws.com/badodemebo/60274544646.pdf
- https://uploads.strikinglycdn.com/files/7c87351f-7064-4cf7-9d90-e9d457249579/torajala.pdf
- https://uploads.strikinglycdn.com/files/80cd58d8-c491-49ed-b4d9-2353ef52f587/what_is_pmi_capm_certification.pdf
- https://s3.amazonaws.com/kufazete/common_core_standards_ela_grade_3.pdf
- https://uploads.strikinglycdn.com/files/79c7801c-7daa-452d-9617-b452adfa6419/amazon_prime_z_the_beginning_of_everything_season_2.pdf
- https://s3.amazonaws.com/petubapizo/wowezefirevikisenulilemej.pdf
- https://s3.amazonaws.com/minaxigevani/pepelalilapafemu.pdf
- https://uploads.strikinglycdn.com/files/55969ceb-8f19-4d04-b1a9-715ef75abb37/wayne_dalton_garage_door_spring_tension.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011ab7.bin2ffab2600868e7287b55ff2cbf5f1be25340cb13f9e41eec7172b578aceca107 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11AB7 | 4704 bytes |
font_01_sfnt_off00012ad4.bin2d3ce2933e625bef57c8cc4edf7453bd0e0968dcd0cabe1720fda08162f2f6c1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12AD4 | 11444 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.