MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=what+are+the+five+stages+of+group+development+mgmt623 PDF link annotation
- https://cdn-cms.f-static.net/uploads/4393018/normal_601cdc00f247c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4425924/normal_603d0b182ef91.pdfIn PDF document text
- http://dixojele.22web.org/22597675507.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4413475/normal_5fcb6dbd17d8e.pdfIn PDF document text
- http://waxopuvuru.22web.org/95587939033.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/sajatofubote/casio_g_shock_wr20bar_change_time.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8ffcae74-e1f8-40d4-b760-c819a471324a/vidotuxisijadubeze.pdfIn PDF document text
- https://s3.amazonaws.com/kegubinefuda/framed_ink_mega.pdfIn PDF document text
- https://s3.amazonaws.com/zesotat/how_to_fix_lazy_boy_recliner_seat.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/289c455b-d50b-41ce-8272-73ae8d1599d5/kilokukewitatewewexaworu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/70c28a7a-bb46-4b40-b3ad-f0678935223e/bajar_biblia_de_estudio_vida_plena_gratis.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/82ddaae4-2d3a-495f-ada7-0f4ac981cbd2/6184639905.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b68a40f9-678b-4962-b3ef-2ded1c1e3386/how_to_make_bean_bags_for_throwing.pdfIn PDF document text
- http://nemojasa.epizy.com/who_is_related_to_zeus.pdfIn PDF document text
- https://s3.amazonaws.com/dazawojob/laruvakos.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9d63f5f7-9d2b-4aa1-96d9-7ca199e45622/farerokasadopevero.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/99395c4c-ee06-4659-bd72-6042f5535cf3/22651360117.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b8e5727f-cd70-4158-982c-d681a6c4bbf1/muwumekogisenubod.pdfIn PDF document text
- https://s3.amazonaws.com/bomupi/java_8_certification_exam_pattern.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f73e85d5-e17a-4623-a389-1c7a5e2a7017/is_twilight_on_amazon_prime_2021.pdfIn PDF document text
- https://s3.amazonaws.com/kisimujuk/45054970715.pdfIn PDF document text
- https://s3.amazonaws.com/jamuluvuvava/salesetofebodexeva.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/315f1f82-1d67-40a9-8411-d9fda9bfa58d/64779105497.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e7aa.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE7AA | 5980 bytes |
SHA-256: 4ef8f3a7dee067654af46e444a2dca7fd46e73e079282bd52d5681612419b35c |
|||
font_01_sfnt_off0000fbf2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFBF2 | 10248 bytes |
SHA-256: 9ab29d1dc883a2a31891bb4392770014e595dc1d7dbb0426fe4f55e597a9aecc |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.