MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafffi.ru/strik?utm_term=my+dolphin+show+8+free+online PDF link annotation
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://static1.squarespace.com/static/5fc0d57abd14ff0dd29c5223/t/5fc0f8534e98326c023328b6/1606482004248/avengers_endgame_wallpapers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2e70abc4-a922-4e49-b862-1426968a5170/jugunutiwe.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fedcf002-c2f3-45ba-8c63-8ffc9088300e/54079077834.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc654f240f1034a5ccdd6fc/t/5fcc99907ae85b53b28cc94a/1607244176857/15278151343.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc2ebbeff13940aa24cd01f/t/5fd1e4e3fec2791e31097382/1607591140668/cold_abscess_symptoms.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4ba44047-ea3e-49bf-8387-ff02e677ea35/44898786117.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc548af9955c744b5585162/t/5fc8a7d626a3037b43412eab/1606985687959/death_coming_game_free.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc575ad2bbd740658254770/t/5fd161eba9eaf43bd846cff8/1607557613552/mow_zombies_mysterious_gun_unlock.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc5073312facd59cec7706f/t/5fcc7f382fa8bc6bcde276bd/1607237433196/ski_safari_online_spielen.pdfIn PDF document text
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe0bef3c6ccf69f325e9ee/1606290423334/cochlear_rechargeable_battery.pdfIn PDF document text
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdf3675147b14804f81b10/1606284135724/43623827664.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5d70cac5-8429-4de3-8835-1f21df077871/roralovisezujoxiju.pdfIn PDF document text
- https://s3.amazonaws.com/baxadelefofibuz/73292005017.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00012479.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12479 | 5312 bytes |
SHA-256: 162a63c8c5f5f0e8aee434ffe1a8e42f1b16d84969f0bed620b4e3333ebdbf00 |
|||
font_01_sfnt_off000136b2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x136B2 | 10524 bytes |
SHA-256: 98456208b7ec5d56b3a9c5a88618635d9bf49ae8bcd1319888d796c02213f08c |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.