MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a heuristic indicating an external URI, which points to a suspicious domain. The document body, though heavily obfuscated, contains references to 'Kahlil Gibran short stories pdf' and 'wkhtmltopdf', suggesting a lure to disguise the malicious intent. The ML classifier and ClamAV detection strongly indicate maliciousness, likely related to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/strik?utm_term=kahlil+gibran+short+stories+pdf PDF link annotation
- https://cdn-cms.f-static.net/uploads/4374857/normal_60139462f124a.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4371240/normal_5fc760e4140fb.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4471690/normal_604b0c00c6b13.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4488581/normal_6023da2a45e1e.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4500887/normal_5fecef622a8d7.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4415065/normal_5fd66780e06db.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4488137/normal_60113be3c0521.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4494431/normal_5ffb253edb4cd.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4454429/normal_603cccbfd7c48.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4496853/normal_5ff4ce90532df.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/b2fec1a3-e86a-4414-b470-c92332b487c8/types_of_phonics_instruction.pdfIn PDF document text
- https://s3.amazonaws.com/rafiralexezol/agile_coaching_book.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2aacc722-f8c9-442b-85af-7f7774474f78/sony_cyber-shot_rx100_iv_price.pdfIn PDF document text
- https://s3.amazonaws.com/kijelopazekune/vunadarisadagerajexukixep.pdfIn PDF document text
- https://s3.amazonaws.com/tonemakopinibem/cruyff_shoes_size_guide.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/eea41ce6-9223-46c9-86ee-3924461cd075/92473426728.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/459343b7-1a14-487d-9ff7-8ce036773a55/neverending_story_big_dog_name.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4699b0bc-2243-448a-a236-a38dccc1abcd/itil_v3_foundation_certification_body.pdfIn PDF document text
- https://s3.amazonaws.com/perurulexi/e39_auto_to_manual_swap.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1eeae11d-88d1-4e58-968e-9231d818557f/foreign_direct_investment_books.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eab7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEAB7 | 5412 bytes |
SHA-256: f7765d7e130c1df2ac60895404182ee7176fec9b29453e728e1b09453111adfb |
|||
font_01_sfnt_off0000fd16.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFD16 | 10372 bytes |
SHA-256: 25d27a5e6a088e02cf52fe04faf2812b58d166188020e87690876cb353679e92 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.