MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged by multiple heuristics and a machine learning classifier as malicious, with ClamAV identifying it as Pdf.Phishing.Trojan. The embedded URL suggests a phishing lure related to a popular artist's album, likely intended to trick users into downloading malware. No scripts were extracted, but the PDF structure itself contains malicious indicators.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/wix?keyword=taylor+swift+red+album+deluxe+edition+free+download+zip
- https://liwevapazu.weebly.com/uploads/1/3/1/0/131071299/xiwomejorib.pdf
- https://wufezaju.weebly.com/uploads/1/3/0/7/130738917/sixomodokonexiz.pdf
- http://wixiziz.iblogger.org/bounty_hunter_guide_elite_dangerous.pdf
- https://ranezilipevag.weebly.com/uploads/1/3/5/3/135392607/lakowixezonode-mugimekineseja-vosipizegu.pdf
- https://wagetuve.weebly.com/uploads/1/3/5/3/135323282/nomojom_xatabi.pdf
- https://fukokegoxa.weebly.com/uploads/1/3/4/4/134463136/renike-kewixalotada.pdf
- https://gojojiwegojefuw.weebly.com/uploads/1/3/2/6/132695574/5840798.pdf
- https://poxobavu.weebly.com/uploads/1/3/1/4/131453713/woduzatenavedep-titituva.pdf
- http://mafejaruvoje.sportsontheweb.net/pdf_to_word_converter_free_nitro_cloud.pdf
- http://mizizufiku.mywebcommunity.org/doduxum.pdf
- https://waxosutuj.weebly.com/uploads/1/3/1/4/131437699/posujokigijod.pdf
- https://nupetumagapet.weebly.com/uploads/1/3/1/8/131859993/a9cf2c.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://dibezul.epizy.com/7099381959.pdf
- https://uploads.strikinglycdn.com/files/cf99b8f6-c575-42ea-a5d4-0b16e1ea6c33/91706014348.pdf
- http://tebaputazaxuva.myartsonline.com/94490374811.pdf
- https://s3.amazonaws.com/jutenojamega/kexibuludilagegarar.pdf
- https://uploads.strikinglycdn.com/files/cfa2e15c-cbb9-4d41-9b30-631c4fe94f4c/57265815148.pdf
- http://miwufojo.epizy.com/bokaju.pdf
- https://s3.amazonaws.com/zifozujiwi/babunademed.pdf
- http://befokube.rf.gd/who_is_the_father_of_progressive_education.pdf
- http://komoxabe.epizy.com/bnf_2020.pdf
- https://uploads.strikinglycdn.com/files/5cbc9f31-d6f0-4f0e-ad6f-ffaf322c451d/popular_old_black_gospel_songs.pdf
- https://s3.amazonaws.com/xamapebonijos/99170100382.pdf
- http://kawerulim.onlinewebshop.net/wazaxajefetomi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1aa.binaf64bd309f4e05c8786f4198c49809bec8dff7327bcddf869a5a8c9f85ddddcd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1AA | 5588 bytes |
font_01_sfnt_off000104b3.bin8087eab50922ec4a06d5c744a1662db1a905b95cec5dee5da7d5d25720b4ed79 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x104B3 | 11972 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.