MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains an embedded URL that redirects to a malicious domain, disguised as a search result for a document. This technique is commonly used in phishing campaigns to redirect users to malicious websites. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/wix?keyword=six+sigma+black+belt+pdf
- https://static.s123-cdn-static.com/uploads/4470683/normal_5fff67147ef63.pdf
- https://cdn-cms.f-static.net/uploads/4412761/normal_601714b6746ce.pdf
- https://cdn-cms.f-static.net/uploads/4375909/normal_6038cee675144.pdf
- https://static.s123-cdn-static.com/uploads/4470692/normal_5ffbf4cfe0110.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/wusone/asbestos_report.pdf
- https://uploads.strikinglycdn.com/files/6e72e44b-11e8-4556-add8-07942a158579/meselumoxibezosiwixid.pdf
- https://uploads.strikinglycdn.com/files/e72270fd-3341-4e61-90d8-5c6329c25c36/samsung_galaxy_note_4_fast_charging_cable.pdf
- https://uploads.strikinglycdn.com/files/83d4a2d7-1842-4188-9bf4-57e4f39c160d/wd_my_cloud_mirror_nas_drive_16tb.pdf
- https://uploads.strikinglycdn.com/files/82d752b5-fdcb-41f6-a19b-60f7f8702d2e/1074750248.pdf
- https://uploads.strikinglycdn.com/files/260b8c90-be0a-4f82-9896-8a34c14e9e87/amar_o_depender.pdf
- https://uploads.strikinglycdn.com/files/e54de9e7-2679-4571-8233-ee91115f8ace/does_microsoft_sculpt_keyboard_work_with_mac.pdf
- https://s3.amazonaws.com/vinejivunitego/90920495335.pdf
- https://s3.amazonaws.com/wamatasamegu/instagram_video_app.pdf
- https://s3.amazonaws.com/xotomisen/nesilatofolojenotox.pdf
- https://uploads.strikinglycdn.com/files/ac4c01eb-ecea-4a9d-8b39-531a8fd3c9ee/taronimufediba.pdf
- https://uploads.strikinglycdn.com/files/153d8bc2-302c-4230-b6fa-e8e2012c499f/31579133780.pdf
- https://uploads.strikinglycdn.com/files/42e87e32-5b3f-4202-8456-b00fb9019c0d/kinibewenabasi.pdf
- https://s3.amazonaws.com/viwoxuz/marine_electrical_systems.pdf
- https://uploads.strikinglycdn.com/files/5e71f179-d09d-40b0-a932-22bc3c347da2/how_to_clean_upholstery_with_the_bissell_proheat_2x.pdf
- https://uploads.strikinglycdn.com/files/691d3475-fb67-4286-a8bc-36a9385e085a/fegolojituvafagoruso.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eabe.bin5510861e0701cb7f7f57c1c4f6c9cfe19f8a483cefdede93edc0bf9cc0aea221 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEABE | 3080 bytes |
font_01_sfnt_off0000f5c6.bin3b561a650d00f8ac945ccb9d3faa745958d36bccc846fa19888daa279a9f5c41 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF5C6 | 5756 bytes |
font_02_sfnt_off00010953.binf43bacb9f7c890c8cd114b0731a3493dce01274a6595b1d3e7fb038abbf11bfb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10953 | 11424 bytes |
font_03_sfnt_off00012f98.bin4ef9506ee11a349461550e6b437e3786686b598308a87786035880d16624999d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12F98 | 16060 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.