MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://fokemale.ru/strik?utm_term=stopping+by+woods+on+a+snowy+evening+analysis+shmoop PDF link annotation
- https://cdn.sqhk.co/jelivapizivo/dVia3jj/destiny_2_pc_build_part_picker.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4469863/normal_6060396f63907.pdfIn PDF document text
- https://cdn.sqhk.co/kovezozeseg/1jhYCLu/chargepoint_apple_wallet_not_working.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4454179/normal_6030cfda60445.pdfIn PDF document text
- https://cdn.sqhk.co/gitopedevid/lif4oij/36877609573.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4426257/normal_605c94f6cea93.pdfIn PDF document text
- https://cdn.sqhk.co/tidilotofuka/pjb0Yhb/borderlands_3_pc_performance_patch.pdfIn PDF document text
- https://cdn.sqhk.co/fuvavegipap/bIaidNO/fevarosebubus.pdfIn PDF document text
- https://cdn.sqhk.co/pesuxitum/hihcRA3/97341834377.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4427821/normal_5fce4bddb9e9b.pdfIn PDF document text
- https://cdn.sqhk.co/nuzinipaz/getzmmj/agnidevan_malayalam_film_songs_free.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/c0e62231-dc06-4978-85df-dfa6e1637d1b/kefifumivomo.pdfIn PDF document text
- https://s3.amazonaws.com/xeruxaxer/affirmative_sentence_worksheet.pdfIn PDF document text
- https://s3.amazonaws.com/xixonu/rinineranisibomu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/345a78d5-ac42-4729-b2c1-90b0236a76e9/how_to_use_fl_studio_on_2_monitors.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/be973a0c-3ee4-416a-b91a-91ae925c55e3/bn_mixer_mackie_1402_vlz_pro.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/52b2e536-51dd-4a87-9f8d-176ca9707a7a/surobemojazamamilatupoliw.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4f83d50c-a1bf-4048-be46-21a321c48f78/are_all_abnormal_moles_cancerous.pdfIn PDF document text
- https://s3.amazonaws.com/savukojubusum/vuladipivinuxuwizuwuge.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4be038f6-bc85-4841-9463-8a2959adcd2a/murray_riding_mower_battery_voltage.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a6626fe3-f43c-42c4-9c57-666ccb48738f/49830238942.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6aca130d-5f9c-4c90-9248-45fd21cf7f1f/basic_mechanical_engineering_gtu_book_download.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f415.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF415 | 5776 bytes |
SHA-256: f9d40e91ceb2a8b59b9d9e1f6a73445096906f36e572a54b867e0ff03f3dfda1 |
|||
font_01_sfnt_off000107ae.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x107AE | 10424 bytes |
SHA-256: 9e18a122cd8128818cda0644e75c354d2968f4d3e92f4cb12f3304d401e28065 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.