MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The sample is a PDF file flagged by ML classifiers and ClamAV as malicious. It contains an embedded URL pointing to a suspicious domain, likely intended to deliver a secondary payload. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document may instruct the user to open a password-protected archive, a common tactic to bypass initial security scans.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=unknown+ultimate+mod+menu
- https://cdn.sqhk.co/durotula/idifhju/sound_effects_app_free.pdf
- https://cdn.sqhk.co/rokedoneja/vigibwX/46516992881.pdf
- https://cdn.sqhk.co/rorajakura/ZhijcaR/fake_caller_anonymous_talk.pdf
- https://cdn.sqhk.co/taxodisilif/hoKf6hV/pocket_academy_zero_mod_apk_android_1.pdf
- https://cdn.sqhk.co/judawube/gijg54d/1097276062.pdf
- https://cdn.sqhk.co/nitagalut/hjfhjgi/11528257174.pdf
- https://cdn.sqhk.co/zikegasenar/giJKqwZ/pocket_academy_zero_apk_mod.pdf
- https://cdn.sqhk.co/vuzujugasije/f1jb4jc/vivinotuniziroz.pdf
- https://cdn.sqhk.co/molodomo/5Mhfgik/79528288458.pdf
- https://cdn.sqhk.co/xufojidaju/qbOgcif/mein_schiff_2_neu_2019.pdf
- https://cdn.sqhk.co/tiwopaperuv/6gfji9Z/41162632148.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/5b8c3eea-d037-45ec-935d-21b07f292336/how_to_setup_a_canon_printer_to_the_wifi.pdf
- https://uploads.strikinglycdn.com/files/972245fc-1e12-4519-b9a6-0f698d0720c6/41276222278.pdf
- https://uploads.strikinglycdn.com/files/39397a1f-e91c-4631-a9eb-5ca3c460a875/78958179990.pdf
- https://uploads.strikinglycdn.com/files/b408b56c-92aa-43a7-b0eb-0597dbec0136/2007_bmw_x3_3.0_oil_reset.pdf
- https://uploads.strikinglycdn.com/files/016386e1-cb9d-46ed-9926-aa57f62bbc31/xfinity_x1_rf_remote_setup_onn.pdf
- https://uploads.strikinglycdn.com/files/b7dc5b25-c4e2-49be-8814-1f320b297e18/canon_mg6320_b200_error.pdf
- https://uploads.strikinglycdn.com/files/c2d42c74-bf28-4435-9fea-c143d0bfd112/delta_flight_attendant_pay_rate.pdf
- https://uploads.strikinglycdn.com/files/28e798b7-d1f8-4e3f-8a3c-f25958515dbd/modern_calligraphy_alphabet_practice_sheets.pdf
- https://uploads.strikinglycdn.com/files/93f372b6-9314-40ef-999d-961a7fee44a2/free_maths_worksheets_for_7-8_year_olds.pdf
- https://uploads.strikinglycdn.com/files/a081d920-56ac-4db4-a8e9-55f4ee879261/coloring_learn_mod_apk.pdf
- https://uploads.strikinglycdn.com/files/846db21e-4488-4aac-8c2b-83346efb9bd5/football_manager_handheld_2021_apk.pdf
- https://uploads.strikinglycdn.com/files/7f599854-7c8b-4759-8806-70a1292f1234/crack_nitro_pro_9.5.4.22_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://sinhala.sourceforge.net/
- http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITS
- http://www.gnu.org/licenses/gpl-2.0.html
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010d28.bin679ef1e67a4c20dc5d7f41c80133d2388335d4535e97b2c24e2bb8ae3fffb9f6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10D28 | 4844 bytes |
font_01_sfnt_off00011d67.bin5b8e8035f8940535bfb5f3d78de7d5c45dbc51c905faa5d9788b8fc152e96872 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11D67 | 3840 bytes |
font_02_sfnt_off00012b78.bin66f217416b4d08e1c1e9205370693be4e11f0e4485e450c8b84896ccdf721fb2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12B78 | 12448 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.