MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains heuristics indicating external URI usage and is flagged by a machine learning classifier and ClamAV as malicious. The document body, though heavily obfuscated, appears to be a lure related to a book summary. The embedded URL `https://pelibifir.ru/strik?utm_term=resumen+del+libro+tus+zonas+erroneas+por+capitulos` is the most prominent IOC, suggesting a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/strik?utm_term=resumen+del+libro+tus+zonas+erroneas+por+capitulos PDF link annotation
- http://sberhome.ru/413000879193s2on.pdfIn PDF document text
- http://jumbochecker.com/what_is_a_crp-hs_blood_testks2yg.pdfIn PDF document text
- http://kfnwejfnkwheklf.space/uk_visit_visa_application_form_from_usabkmax.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4413862/normal_6048c14e2e79d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4420599/normal_601749890dc5c.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4402944/normal_5fe454586c1f5.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4427783/normal_5fccbbf71440f.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4459027/normal_5fe22d03c915e.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4369505/normal_5fe0f2961d31a.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4408471/normal_603f551e93242.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4489730/normal_604d13ce59f2c.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/e455e175-078c-488b-8df8-ae038892151b/motorola_bluetooth_headset_setup.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5b99f0e7-4449-4ab2-962a-59334930ed1b/vokodemokalutom.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2571a1ec-a921-4e53-9957-bffcefc5c798/how_much_weight_can_a_2017_nissan_pathfinder_tow.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/359a1147-4b93-47d6-9c1e-882caba77e6b/mozajudigeneme.pdfIn PDF document text
- https://s3.amazonaws.com/bupaxomu/gantz_perfect_answer_streaming_ita.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ace523c2-43eb-4d71-a2d3-a187aa898ef7/9700074635.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2f094d46-d9e8-4d61-82b1-cdf7a12e0ffe/28932227706.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ccec0703-b02c-4110-9628-9eba5a10e371/why_wont_my_apple_tv_remote_control_volume.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/93a40f9c-8e89-43eb-841d-4f400a6f17f1/page_break_preview_in_excel_online.pdfIn PDF document text
- https://s3.amazonaws.com/nelizenejakarug/logo_quiz_answers_level_10_iphone.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1e0d0c53-38db-4844-8866-e7307c04067a/best_business_communication_courses.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00015b47.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15B47 | 5416 bytes |
SHA-256: 66dd75971a6900dd59af4c4af590beb46b25ac567ca62de5c0dd6d60ffa03d5f |
|||
font_01_sfnt_off00016d9f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16D9F | 12288 bytes |
SHA-256: 01e915ed3decfd7456613696a0ad0839cf953a2141fa3da563343bc31ff6daf8 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.