MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ClamAV and an ML classifier, with high-severity heuristics indicating suspicious links to external domains. The presence of multiple embedded URLs, including one disguised as a PDF on a suspicious domain, strongly suggests a phishing or malware distribution attempt. The document body, though heavily obfuscated, contains metadata related to wkhtmltopdf, indicating it might be a generated document used to mask malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9961
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LUREPDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://baarspo.ru/wix?keyword=minion+hair+salon+game
- http://pukatasenibi.iblogger.org/movie_sequels_coming_out_in_2021.pdf
- http://uaregroup.com/vudejorojejejef9cw1l.pdf
- https://cdn.sqhk.co/musutalivun/cxPPP2Y/bubble_shooter_2020.pdf
- http://mavito.online/app_store_free_for_macw2ibp.pdf
- http://capridigi.com/abyssinica_amharic_keyboard_for_macp95ib.pdf
- https://cdn.sqhk.co/xawodoze/uuijibm/snapple_k_cups_discontinued.pdf
- http://loginwithfb.site/90015212062v0gdv.pdf
- https://cdn.sqhk.co/noviraxat/jSvGic2/international_financial_reporting_standards_ifrs_9.pdf
- http://doporujela.iblogger.org/80530419785.pdf
- https://dexazime.weebly.com/uploads/1/3/1/4/131437554/2763555.pdf
- https://bemebedutor.weebly.com/uploads/1/3/4/6/134624352/zopunajila.pdf
- http://uspeh.icu/97577703891u86b.pdf
- https://cdn.sqhk.co/dufikibagi/zSihG44/45230657302.pdf
- http://on-arenas.com/gmat_formula_sheetatq0q.pdf
- http://jijexuvekenim.iblogger.org/sikinevowa.pdf
- https://tebiwexarug.weebly.com/uploads/1/3/1/3/131380746/6321720.pdf
- https://xibokesobapud.weebly.com/uploads/1/3/0/7/130776239/wegolubujoxu.pdf
- http://card2card-perevod24.site/xajigfwtrz.pdf
- http://world-wildshop.com/rogiregoxiwobildgr1.pdf
- http://brightshopbg.xyz/ischgl_snow_report_forecast58x4s.pdf
- http://aov.one/calligraphy_handwriting_practice1aigz.pdf
- https://cdn.sqhk.co/jeporikate/hBuhiE9/48530133127.pdf
- http://justamorem.com/354111222922kef0.pdf
- http://front-glass.website/how_to_make_shadow_puppets_handshedlp.pdf
- http://lnstagramverifiedbadgeshelpcenters.net/play_free_texas_holdem_replay_pokerj1nf6.pdf
- http://zoneeuro.pro/darekidaselokivumam7fgaz.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://temekem.epizy.com/69932953658.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f536.binca7877bba8320645314359def1892824e1c29d480cfd1a2a64c4d1def8238cd2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF536 | 5104 bytes |
font_01_sfnt_off0001066e.bin8016467fe57fc89d8b54f092704c028a2db37adfbb01f2e8b152574fec5f595a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1066E | 10772 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.