MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URL pointing to 'kuzutuzo.ru', which is likely used for phishing or malware distribution. The document body, though heavily obfuscated, suggests a lure related to academic writing, aligning with common social engineering tactics.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=how+to+write+an+abstract+for+a+lab+report+in+biology PDF link annotation
- http://aycotoro6.xyz/48063838110xdar.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4368740/normal_5ffcd87a8ddce.pdfIn PDF document text
- http://serdyukov.pro/bulletstorm_full_clip_edition_om_nom_nom_trophyys89c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4485695/normal_602341e5b6343.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4495399/normal_5fe15088ea9a6.pdfIn PDF document text
- https://cdn.sqhk.co/xupodafib/ibjcjaf/78633574656.pdfIn PDF document text
- https://cdn.sqhk.co/kigoxeni/jbv5ber/new_neo_geo_mvs_games.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4447916/normal_602117f88c017.pdfIn PDF document text
- http://chategratis.online/nipojitozarc9ng.pdfIn PDF document text
- http://teachersaid.fun/677440808296s50h.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4386076/normal_5fef6dcac3541.pdfIn PDF document text
- https://cdn.sqhk.co/gapobuzijiru/GggyidP/old_kingdom_egypt_art_style.pdfIn PDF document text
- http://the-glow.ru/ranaxobuxilixijax1gt31.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4417806/normal_5fcc1612992d0.pdfIn PDF document text
- http://topdiscount.pro/juwopurukeramipovejapcp.pdfIn PDF document text
- http://rankingcoach-apps.com/xefetafuzuwajpz3w5.pdfIn PDF document text
- https://cdn.sqhk.co/jifedibodo/0YG7a40/planetside_2_shattered_warpgate_review.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4475985/normal_603c747bc5860.pdfIn PDF document text
- http://getliterate.online/bullet_bike_sound_videogyfbl.pdfIn PDF document text
- http://poradoit2.site/sagigitatirawipewaffimzb.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4474211/normal_6007e297dbc9a.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010642.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10642 | 5476 bytes |
SHA-256: 4ba51090c7e6ae55bfc2d8fbb1a1fc21ef06bdfabfb2dae821ab6bfc00bd54c1 |
|||
font_01_sfnt_off0001190a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1190A | 10604 bytes |
SHA-256: 3906268a8b716490492e7f61dc10c50b3144b0e0698bb2e75481ca5857bd64dc |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.