MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. It contains an embedded URI pointing to 'resalured.ru', which is likely used to host malicious content or phishing pages. The document body, though heavily obfuscated, suggests a lure related to a 'wiki'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/wix?keyword=volt+white+2+wiki
- http://lastmarkt.ru/the_black_table_is_still_there9qoqd.pdf
- http://vash-komfort5.ru/37368968646z1pjd.pdf
- http://hotita.space/52696532461nt47h.pdf
- http://tuduvodakep.mypressonline.com/kigodotuk.pdf
- http://kostlike.site/how_much_is_robert_greene_worth617h8.pdf
- http://prodit.space/pioneer_vsx-1122_factory_reset4bfmr.pdf
- http://zagejudivavi.sportsontheweb.net/fuwoliganes.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/e968fb11-9734-44ac-88b6-67622cd3f7b1/paxewa.pdf
- https://uploads.strikinglycdn.com/files/76851e0c-dab8-411a-90b2-0423f750b977/stephen_king_the_mist_full_movie.pdf
- https://uploads.strikinglycdn.com/files/662f4742-34ba-4473-83ed-f725aa3401ab/35750953577.pdf
- https://s3.amazonaws.com/patotale/avira_antivirus_pro_apk_full.pdf
- https://uploads.strikinglycdn.com/files/2ddfad36-2f12-40f0-b568-ba078c11db8e/gexezifudutazop.pdf
- https://s3.amazonaws.com/wunojipu/what_are_the_benefits_and_limitations_of_cloud_computing.pdf
- https://uploads.strikinglycdn.com/files/e4167e69-10c8-4db5-82e1-4613eacf743c/python_data_science_essentials_-_third_edition_free_download.pdf
- https://uploads.strikinglycdn.com/files/983adb6b-4161-4b1c-aa17-f1ce88546833/gebukorinipewuta.pdf
- https://s3.amazonaws.com/dubiditiginowo/pufavulepamigodudiru.pdf
- http://kamigawox.atwebpages.com/envision_math_3rd_grade_workbook.pdf
- https://uploads.strikinglycdn.com/files/26510be3-1adf-419e-9e85-3ffe180ce129/wasuguvosixitobezalo.pdf
- https://s3.amazonaws.com/xefejevife/60433382113.pdf
- http://zuvuzevo.atwebpages.com/ados_test.pdf
- https://uploads.strikinglycdn.com/files/03701789-37a9-4038-af91-a8fa54ca8015/tirokokaguxajoxoneli.pdf
- https://uploads.strikinglycdn.com/files/52888cfb-6262-4a28-b2b8-aeb8e79cd9a2/81874148292.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001583a.binf31e19a8c9495587d94aa0be5eca315d05f8453b3d55bd7d06bf0b7521938617 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1583A | 4540 bytes |
font_01_sfnt_off000167c4.bin48127a07e7b85b10fec5c8e8822994e99f4931cde1c1381930f2e87fc2a1f943 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x167C4 | 11316 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.