MALICIOUS
162
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://yafferge.ru/strik?utm_term=does+jack+die+in+jack+frost'. Additionally, the document body, though heavily obfuscated, contains text that suggests an urgency lure, as indicated by the 'SE_URGENCY_LURE' heuristic. ClamAV also detected the file as a phishing trojan. No scripts were extracted, but the presence of a malicious URL strongly suggests an attempt to redirect the user to a phishing or malware distribution site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9929
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://yafferge.ru/strik?utm_term=does+jack+die+in+jack+frost In PDF document text
- http://rugegav.mywebcommunity.org/arabian_dances_flute.pdfIn PDF document text
- http://wewedaz.iblogger.org/autocad_lt_2015_installer.pdfIn PDF document text
- http://wopizup.mypressonline.com/beauty_and_the_beast_2020_movie_script.pdfIn PDF document text
- http://mazikopipovix.mywebcommunity.org/books_of_the_bible_old_and_new_testament_word_search_answers.pdfIn PDF document text
- http://gezudozu.iblogger.org/form_builder_angular_8_example.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://fedorahosted.org/lohitIn PDF document text
- https://uploads.strikinglycdn.com/files/2c3f8ec3-2b11-46f4-b24f-bbf45dceef56/excel_vba_find_and_replace_character_in_string.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/44acc79d-c865-4ccb-95f0-670dfbc64a26/4218287479.pdfIn PDF document text
- https://s3.amazonaws.com/kugelilizibuwum/algebraic_expressions_class_7_worksheets.pdfIn PDF document text
- https://s3.amazonaws.com/zurovajij/809476373.pdfIn PDF document text
- http://tigagatu.atwebpages.com/biosynthesis_of_phenolic_compounds.pdfIn PDF document text
- https://s3.amazonaws.com/bupesejirijejus/56793062423.pdfIn PDF document text
- https://be8f41f0-9ddd-434d-ab6d-aa755a40b80d.filesusr.com/ugd/726d9c_a0582aa40e3a46308e87d2316cbc54c4.pdf?index=trueIn PDF document text
- https://2ac56fc1-f7ee-4366-9cb2-1681469c68ee.filesusr.com/ugd/b914b5_ec45ad911c084836a5e21221c3fbda6b.pdf?index=trueIn PDF document text
- http://xirexadugimog.atwebpages.com/99848644204.pdfIn PDF document text
- https://0c7b1e5d-10e9-4c66-9a64-57e6babc74f3.filesusr.com/ugd/6b59ba_99a74afa811145feaa4e9f27d4392023.pdf?index=trueIn PDF document text
- http://jasesazolaf.myartsonline.com/cabrio_dryer_does_not_heat_samsung.pdfIn PDF document text
- https://s3.amazonaws.com/nakevoja/what_book_is_after_rising_storm.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://www.geocities.com/mitra_anirban/hobbies.htmGNUIn PDF document text
- http://www.gnu.org/copyleft/gpl.htmRegularIn PDF document text
Extracted artifacts 7
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_008_off00018b0a.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x18B0A | 17124 bytes |
SHA-256: affef9101625443fad5a09580eb9c67f3a40150797e5f6e9b27db740eb9b4ad6 |
|||
font_00_sfnt_off00011252.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11252 | 7988 bytes |
SHA-256: a950262607a018bfc8b4142826c39312b464f9defed1a9653233ec380dea7cc0 |
|||
font_01_sfnt_off00012da5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12DA5 | 5124 bytes |
SHA-256: 62b5248ae652da5cc3b335720d6ba169a22a91d893485196397f30f3218c7abb |
|||
font_02_sfnt_off00013f2b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13F2B | 3772 bytes |
SHA-256: 76634ab600986209322857f14b6cae08f909dcb6bf5bd2a55c56778442fa5789 |
|||
font_03_sfnt_off00014d0d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14D0D | 4800 bytes |
SHA-256: f0b95cd2f448e88a2403171c07fa3bcbd8035ff39372372cb291d6443edf5468 |
|||
font_04_sfnt_off00015c96.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15C96 | 14564 bytes |
SHA-256: 2ecc4be6516266645421a9f7a1e36aeeac46e96d820959ac7823601610a38e18 |
|||
font_06_sfnt_off0001a43d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A43D | 3500 bytes |
SHA-256: 04ff50cf57b9bace9a066647f518378a6027fd619d8f269ceecff67bfbb0444e |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.