MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. The embedded URL points to a suspicious domain, suggesting a phishing or malware distribution attempt. No scripts were extracted, but the presence of an external URI is a strong indicator of malicious activity.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://huntic.ru/square?utm_term=ide+meaning+programming
- https://static1.squarespace.com/static/60bf6cad3a95e91b59aa2418/t/60ee6f2bbb85ab7f02bff077/1626238763412/weduwosawugudulitunofe.pdf
- https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60f458869c7c9f0ea9a4449b/1626626182402/77433071240.pdf
- https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f18406b0b7347a52295559/1626440710947/14068197065.pdf
- https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60ed854afc46f1629a066b86/1626178890907/how_to_clean_burnt_plastic_from_oven.pdf
- https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60f0ded8de4abb1f43918a21/1626398424725/pibotero.pdf
- https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e7a8b1b977dd1475c719a7/1625794737574/circumference_of_disc.pdf
- https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60e8d33440fa0f2168475809/1625871156610/1424041546.pdf
- https://static1.squarespace.com/static/60aac4dd19f082755c4e5c69/t/60e7bab24b964f05b8468413/1625799346762/tempering_of_quenched_martensitic_steel_is_necessary_to_improve_the.pdf
- https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e9321fb68d8f0f4bf8d19f/1625895455637/fuzisopakekojuminagale.pdf
- https://static1.squarespace.com/static/60bf69b23f3791685666e32d/t/60e89c926497a9658a2511ed/1625857170291/jokes_and_answers_funny.pdf
- https://static1.squarespace.com/static/60aac5994c6b1805bc4acbdb/t/60f7d2b548de5a6273fb2c69/1626854069945/gurusuzigisateda.pdf
- https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60f43c3926c2747482e86d3f/1626618937205/91957791489.pdf
- https://static1.squarespace.com/static/60aac52a97a1d73ddacfe14c/t/60ec9e8c934d360eb28ad02f/1626119820527/the_big_bang_theory_s03_torrent.pdf
- https://static1.squarespace.com/static/60bf6bff0d8d387fecc8b153/t/60f21ef329712869f05a08f5/1626480371975/ferris_buellers_day_off_soundtrack.pdf
- https://static1.squarespace.com/static/60aac4e0d5abe22cec5c4b22/t/60e8ce15f28789513b647dfb/1625869845671/solving_linear_equations_and_linear_inequalities_practice_problems.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e237.bin8a201bcbb12a93e475d39bb032745617486cc7d1baad3a2c859785e07dc03c24 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE237 | 16700 bytes |
font_01_sfnt_off00010dd8.bin38df9104c6000cc4cb3bd7a8e3e0bbaaad773bc02382a68bbb48dea729ec4df4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10DD8 | 10372 bytes |
font_02_sfnt_off000124f3.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x124F3 | 16792 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.