MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a heuristic indicating an external URI, which points to a URL associated with game cheat searches. This URL is likely used as a lure to direct users to a malicious site. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/wix?keyword=world+conqueror+3+unlimited+medals+android
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/vovuzize/xufifigovulug.pdf
- https://s3.amazonaws.com/ronenitevodo/kutemotexukibibowigufus.pdf
- https://s3.amazonaws.com/sobaketemu/analog_clock_worksheets_grade_2.pdf
- https://uploads.strikinglycdn.com/files/7af53111-f29d-4e21-81c6-98cb5d3737aa/basic_dutch_grammar_book.pdf
- https://uploads.strikinglycdn.com/files/6e5560f2-94f0-4747-ac0d-28eb58cd4361/xovebolava.pdf
- https://uploads.strikinglycdn.com/files/236ce1b9-1924-46b6-9ba3-ed3cc016344f/start_your_own_blogging_business.pdf
- https://s3.amazonaws.com/ropuba/15567994812.pdf
- https://uploads.strikinglycdn.com/files/a49b7050-3537-48cc-ad87-ad2dd4db7f51/26619076858.pdf
- https://uploads.strikinglycdn.com/files/3d333de3-bd77-406f-a5ea-d6e0ef4bd1c2/the_five_dysfunctions_of_a_team_team_assessment_2nd_edition.pdf
- https://s3.amazonaws.com/lorifawuvawot/98274044265.pdf
- https://s3.amazonaws.com/likerajatob/assurance_of_support_release_form.pdf
- https://s3.amazonaws.com/bepukuba/vadakusa.pdf
- https://uploads.strikinglycdn.com/files/135b167f-9489-40c9-932f-fb5b1ac47d30/zunufevififumeputamuwug.pdf
- https://s3.amazonaws.com/daxemo/xezagemev.pdf
- https://s3.amazonaws.com/lurutopobi/kisulakugi.pdf
- https://uploads.strikinglycdn.com/files/5bbbf6c0-ed2b-4415-a684-919ca15d266b/24059501137.pdf
- https://s3.amazonaws.com/sorogamat/treating_chloroform_in_well_water.pdf
- https://s3.amazonaws.com/solonebosop/steam_api64._dll_missing_gta_v.pdf
- https://s3.amazonaws.com/popilo/oops_concepts_in_java_code_project.pdf
- https://s3.amazonaws.com/wixatax/friedrich_nietzsche_books_in_spanish.pdf
- https://s3.amazonaws.com/womirofop/51905784403.pdf
- https://s3.amazonaws.com/loneminovu/surubuparuwukox.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ebe7.bin1ef8da4b0b9130e6d0326f47270eded171ab6971193ce888623a84ed7d097720 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEBE7 | 5388 bytes |
font_01_sfnt_off0000fe27.binee7678323e0a239f899618d192b451d50342971bf4a7bf47d8abad72237ea42f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE27 | 10644 bytes |
font_02_sfnt_off000122e5.bina95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x122E5 | 16204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.