MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. The document body, though heavily obfuscated, contains text related to a 'replacement cartridge for audio technica lp120' and references wkhtmltopdf, suggesting a lure document. An external URI pointing to 'zajinet.ru' was extracted, which is likely the malicious destination.
Machine Learning
- Nyx PDF Classifier malicious score 0.9961
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=replacement+cartridge+for+audio+technica+lp120
- https://cdn.sqhk.co/vonitumefide/Uhdbihj/saint_petersburg_metro_map_english.pdf
- https://cdn.sqhk.co/lalamiteliw/7t5Yhao/remaforafogosedobu.pdf
- http://zuvatewovu.scienceontheweb.net/barron_s_sat_subject_test_physics.pdf
- http://pajuwepubawip.sportsontheweb.net/sozutinotilarewibav.pdf
- http://mojofaza.mypressonline.com/bardo_thodol_romana.pdf
- https://cdn.sqhk.co/dekawako/MgffidR/shankar_dada_mbbs_movie_naa_songs.pdf
- http://dimusenomi.iblogger.org/spring_framework_durgasoft.pdf
- http://xoxuvajes.mywebcommunity.org/bubapumon.pdf
- http://zijukikov.mypressonline.com/ca_final_books_download.pdf
- https://cdn.sqhk.co/zikegasenar/Tc8zYcQ/ligivudosafuvezumisasox.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://wuxininozikup.rf.gd/preparation_of_activated_carbon_from_coconut_shell.pdf
- https://s3.amazonaws.com/kegubinefuda/julunuraraduboreso.pdf
- https://s3.amazonaws.com/bokelur/67538566367.pdf
- https://s3.amazonaws.com/kegubinefuda/how_much_does_it_cost_to_change_motorcycle_oil.pdf
- https://s3.amazonaws.com/viregujipowuru/gudaminapipu.pdf
- https://uploads.strikinglycdn.com/files/e8bbdcfc-c18c-41ab-a1e0-63407247f352/midnight_meaning_in_chinese.pdf
- https://uploads.strikinglycdn.com/files/1d236a2d-91fa-49d5-a4d2-b619b1bfe395/shinco_10000_btu_portable_air_conditioner_reviews.pdf
- https://s3.amazonaws.com/luramamelolem/wubebitotaloxipiso.pdf
- https://s3.amazonaws.com/dipafuxe/xevosopulukabaran.pdf
- https://s3.amazonaws.com/risalenefazozo/punixezapuwedaxogobemenef.pdf
- http://dupepasanu.epizy.com/periodic_table_of_elements_quilt_pattern.pdf
- https://uploads.strikinglycdn.com/files/9eb5b2e9-b4c0-4f2d-af7c-1ba03ca70368/hp_envy_4500_printer_not_printing_photos_properly.pdf
- http://bekegukuvaliji.rf.gd/7657522152.pdf
- https://uploads.strikinglycdn.com/files/4ebe60d2-5142-4035-9724-bef7369f033e/dizufizimikeverigev.pdf
- https://s3.amazonaws.com/zosevid/bafegedepurazexafisudobib.pdf
- https://s3.amazonaws.com/gozilum/672760076.pdf
- http://xolazituvote.epizy.com/94044740678.pdf
- https://uploads.strikinglycdn.com/files/a2ec2d2e-34f1-44e3-ae10-93f25b15bd79/jekarafidurifazu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f480.bin6b25a2acdcc7630b2dcf328cd50b4a76cc13e6b5d357460d674185df89849eb5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF480 | 5724 bytes |
font_01_sfnt_off000107dd.bin74b13b90198cfede97a4c5c4c471d43218f6241f30c7b98e85f4ade4799c46cc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x107DD | 10492 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.