MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URI pointing to 'leonvi.ru', which is flagged as suspicious. ClamAV detection and ML classification strongly indicate maliciousness, classifying it as a phishing trojan. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, a tool often used to create PDF documents from web content, further supporting the lure to an external URL.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=guide+gear+cargo+pants PDF link annotation
- https://cdn-cms.f-static.net/uploads/4419452/normal_601beb852426c.pdfIn PDF document text
- http://jewlgems.com/como_conseguir_lingotes_de_oro_candyjpbua.pdfIn PDF document text
- http://b4shop.icu/animal_english_song_freehaduh.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4403410/normal_6003a9944af6b.pdfIn PDF document text
- https://cdn.sqhk.co/jowibigodene/eHjgiaN/lejol.pdfIn PDF document text
- http://mazafaka69pussy.online/balearia_palma_formentera_directour3hd.pdfIn PDF document text
- https://cdn.sqhk.co/bisulalu/h4uieih/vubavusudinugigud.pdfIn PDF document text
- http://sugoxebojun.getenjoyment.net/88349494613.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4393893/normal_5fee8f6c77206.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4407064/normal_5fcf50204f3fa.pdfIn PDF document text
- http://jonotijero.medianewsonline.com/bebixosafolugot.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/zesixefe/how_to_use_canon_f_718sga_scientific_calculator.pdfIn PDF document text
- https://s3.amazonaws.com/batoragubukepo/melim.pdfIn PDF document text
- https://s3.amazonaws.com/jefobexapulow/xozeseraraxax.pdfIn PDF document text
- https://5a98ae10-8c7e-48da-b83f-9bcbc644cfa3.filesusr.com/ugd/9a8764_53888c3c2b964ff29c9f469110ec4f2a.pdf?index=trueIn PDF document text
- https://4b4ea461-5266-411b-8735-d5290551f550.filesusr.com/ugd/7fedcf_511ae59c41a94a3599358a946eb7f046.pdf?index=trueIn PDF document text
- https://03df18d0-0a94-4077-8b44-1f3cf8b7c870.filesusr.com/ugd/23a6c3_76893804b2eb46b6b105846d86eedfd3.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/megujobemegor/baby_shark_original_video.pdfIn PDF document text
- https://010f2e21-25ca-4560-806d-08cbbb7c7db1.filesusr.com/ugd/74a852_5d598b124d1a4b8c9c9802ca514543e5.pdf?index=trueIn PDF document text
- http://vuzuwukef.atwebpages.com/marx_capital_and_the_madness_of_economic_reason.pdfIn PDF document text
- http://zowofiz.myartsonline.com/stepwise_regression_spss.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ebce.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEBCE | 5240 bytes |
SHA-256: 566182fe26ca1f7bede75a82ebe69d3ac11f0fc940edf142d3651b42aeb78f66 |
|||
font_01_sfnt_off0000fdb6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFDB6 | 11216 bytes |
SHA-256: 8d6e091ae73754aa76c0e48ae2a9254e25e9c4199e256f7160f19cab4698f17c |
|||
font_02_sfnt_off0001242c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1242C | 16140 bytes |
SHA-256: 1ffca1ef16be5e2ec436e77f9211a88ad3199dc781cb76600401cc2e2c7dce6d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.