MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URL, https://resalured.ru/123?utm_term=1040x+amended+tax+form+2016, which is likely the primary vector for the attack. The document body, though heavily obfuscated, suggests a lure related to tax forms, aligning with common phishing tactics.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/123?utm_term=1040x+amended+tax+form+2016
- https://static.s123-cdn-static.com/uploads/4489237/normal_5fcf5852576cc.pdf
- https://cdn-cms.f-static.net/uploads/4383444/normal_601a4ac0018c7.pdf
- https://cdn-cms.f-static.net/uploads/4422627/normal_60608ef88b626.pdf
- http://golesaluwo.66ghz.com/pdf_auditing_standards.pdf
- http://mon-cmso.best/free_printable_synonym_worksheets_for_5th_gradecz6lv.pdf
- https://cdn-cms.f-static.net/uploads/4376599/normal_602de2c810de7.pdf
- http://esparks.ru/does_gamestop_fix_nintendo_dswfc5z.pdf
- http://wuwulobuxalajut.iblogger.org/43219509360.pdf
- http://belplitka.ru/highway_to_heaven_song_lyrics_nctf9hsl.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/bd216ddf-609e-45bc-a658-3994d458f928/washington_dc_covid_19_vaccine_sign_up.pdf
- https://uploads.strikinglycdn.com/files/dc3ec7e2-5694-4c8a-91b3-e2d18a29a794/dezenaxo.pdf
- https://uploads.strikinglycdn.com/files/d4d83928-0d00-435a-9730-a0ff237145ca/begeleg.pdf
- https://s3.amazonaws.com/gelawiweza/35533344738.pdf
- https://uploads.strikinglycdn.com/files/371bb0af-6c11-4dc5-978f-057011fb8acc/leposatamidaniso.pdf
- https://uploads.strikinglycdn.com/files/82828b56-370a-4ec5-8649-534f47aeaab0/rivorakobujifiv.pdf
- https://uploads.strikinglycdn.com/files/77408272-d240-4910-a254-9c07ed37bea3/84529823904.pdf
- https://uploads.strikinglycdn.com/files/2101f025-d548-4b8f-b6cd-c5b04721c51b/93215765602.pdf
- https://uploads.strikinglycdn.com/files/62d4d650-9255-4f36-ba8d-2c2e6eb9c79f/2105156998.pdf
- https://uploads.strikinglycdn.com/files/5244acbc-ab45-4baa-bb37-e7dc81986f2e/garmin_94sv_plus_livescope.pdf
- https://s3.amazonaws.com/netinuwa/the_most_dangerous_game_question_support_answers.pdf
- http://zalowakudedakov.rf.gd/yasin_suresi_latince.pdf
- https://s3.amazonaws.com/dejolavubukugeb/8146624657.pdf
- https://s3.amazonaws.com/pusori/ruduwutikokanugazo.pdf
- https://s3.amazonaws.com/gagotaniwipure/rudonoronafapafi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e6d8.bind28ae7ba77208c83c935f7efca4a069d74d18ede71be6bea51cdab9340a5517e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE6D8 | 5124 bytes |
font_01_sfnt_off0000f824.bin1e72bca6ed667fc793262f6ce44681e7c838fa1baf9293e5e63df9e1acf393ef |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF824 | 10608 bytes |
font_02_sfnt_off00011c87.bince7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11C87 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.