MALICIOUS
104
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains an external URI pointing to 'vilenefex.ru', which is likely part of the lure to download a payload. The document body, though truncated and obfuscated, suggests a theme of free website templates, aligning with a phishing pretext.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/123?utm_term=free+website+templates+for+photography+business
- https://cdn.sqhk.co/bogovureg/ficfxgd/nowikeririvupe.pdf
- https://cdn.sqhk.co/kavejufa/rjjhige/mlb_news_and_rumors_red_sox.pdf
- http://durowan.sportsontheweb.net/6224086760.pdf
- https://cdn.sqhk.co/kifukuvitog/Voiidgg/hide_and_seek_korean_movie_netflix.pdf
- https://cdn.sqhk.co/paxelababeg/cNjheji/51385303013.pdf
- https://static.s123-cdn-static.com/uploads/4409616/normal_6000ed8285b56.pdf
- https://cdn-cms.f-static.net/uploads/4485434/normal_60511c27d36e8.pdf
- http://bekunogoxabune.iblogger.org/326516827.pdf
- https://cdn-cms.f-static.net/uploads/4471275/normal_601ef196eaf0c.pdf
- https://static.s123-cdn-static.com/uploads/4417423/normal_5ff3d70ce3527.pdf
- http://kajejib.medianewsonline.com/zubiwagaredi.pdf
- https://cdn-cms.f-static.net/uploads/4457620/normal_5feaec89d73b5.pdf
- http://kudonolenukiv.22web.org/how_do_i_connect_my_canon_pixma_mg2520_printer_to_wifi.pdf
- http://tixobikoxemegor.22web.org/55657086809.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://254a6a59-343e-4b7e-907c-c4819e171fff.filesusr.com/ugd/decf6f_06558450117a46ad9b4d10951f42e983.pdf?index=true
- https://f59c0a4d-c104-43ac-8966-a5978cdf1b8c.filesusr.com/ugd/0c1ebd_1c1f9fb691c04bc6a05b9ec3ec2d94fb.pdf?index=true
- https://0306adf0-382e-42f1-903d-71c3961c97f1.filesusr.com/ugd/7ff653_bf44f3d172d4492983eed7a9f290b542.pdf?index=true
- http://zepibugab.rf.gd/3942890418.pdf
- http://palezonipegodaf.epizy.com/79506055611.pdf
- https://uploads.strikinglycdn.com/files/dfd99a34-7adf-403d-b741-62618a3c012f/84334258195.pdf
- https://uploads.strikinglycdn.com/files/11eb7dec-acc4-44b8-b995-90cba22c8884/are_romeo_y_julieta_cigars_good.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00029122.bin618cc86c7f32c57dde520a26c5579d4cf88457c33a1742aa6c7f5d91aac32785 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x29122 | 5604 bytes |
font_01_sfnt_off0002a41d.bin3d6f535bc368d639d0f4b89a8e2e6cb0af140569d70e2bae774be9489481d539 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2A41D | 11540 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.