MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a heuristic firing for an external URI, pointing to a suspicious domain. The ML classifier and ClamAV detection strongly indicate maliciousness. The embedded URL is likely intended to redirect the user to a phishing or malware distribution site, disguised as a worksheet answer key.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/strik?utm_term=area+of+composite+figures+worksheet+6th+grade+answers
- http://vigemej.iblogger.org/11576114473.pdf
- http://gubokiwurajot.iblogger.org/mowesufoboges.pdf
- http://xonibiz.22web.org/mandated_reporter_nysed.pdf
- http://vuvubul.iblogger.org/25009418888.pdf
- http://novedexezenel.66ghz.com/87492392936.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/xesigeze/private_practice_cast_season_3_episode_6.pdf
- http://rujipezoj.epizy.com/breakthrough_prayer_jim_cymbala.pdf
- http://wonenuw.epizy.com/tebaxen.pdf
- https://s3.amazonaws.com/rakabexozu/kathai_tamil_movie_song.pdf
- https://uploads.strikinglycdn.com/files/3bc003e8-51bf-4ab4-bf9a-4bb4474f5a6b/borikugogidegegelawura.pdf
- https://s3.amazonaws.com/xeponodij/how_to_say_jesus_prayer_in_greek.pdf
- https://s3.amazonaws.com/kalanejaxutilif/gracie_barra_jiu_jitsu_curriculum.pdf
- http://ninalosuza.rf.gd/26326954730.pdf
- https://uploads.strikinglycdn.com/files/30f0074d-c4d9-4b7c-9319-092cc920303e/are_permit_test_multiple_choice.pdf
- https://uploads.strikinglycdn.com/files/097a5a9f-ad2f-46d3-b866-01285b70495e/ham_without_oven_bagel.pdf
- http://gefosudevepap.rf.gd/93251597301.pdf
- http://dimonejoxu.rf.gd/frp_bypass_app_for_android.pdf
- http://vezuxafafifobo.epizy.com/is_aircraft_maintenance_in_demand.pdf
- https://uploads.strikinglycdn.com/files/541afd5b-3468-41ae-b261-f984709a265a/kaplan_mcat_practice_test.pdf
- https://s3.amazonaws.com/bugutaj/begatajimegilenevejimuze.pdf
- https://uploads.strikinglycdn.com/files/e060fedf-9788-4f4d-9664-b50d2afb5d9e/how_much_does_sweat_bbg_cost.pdf
- https://uploads.strikinglycdn.com/files/65d3b875-93b7-418c-bfec-59e4602038d4/how_do_i_connect_my_bluetooth_keyboard_and_mouse_to_my_mac.pdf
- https://uploads.strikinglycdn.com/files/e04a3686-de43-4593-a2ff-6e2291b04790/nosler_load_data_6.5_creedmoor.pdf
- http://dexifuv.epizy.com/bissell_powerforce_compact_turbo_bagless_vacuum_cleaner_2690.pdf
- https://uploads.strikinglycdn.com/files/7a47eb35-6898-4646-9b5a-27586beb8162/do_steam_dryers_hook_up_to_cold_or_hot_water.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f88e.binb99a0faf954bebef9187c99cf6f8df2d4984dfece1f2fbf0c1afe1737be75e32 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF88E | 5836 bytes |
font_01_sfnt_off00010c5a.bin81709812874d17a757d8e99df4215aeec3a07d1470e8db046a3e13cf84e970ee |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10C5A | 11164 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.