MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file contains a link to a known malicious redirector, indicating a phishing or scam attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. The embedded URL is likely used to deliver a second-stage payload or redirect the user to a phishing site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=template+wedding+filmora+free In PDF document text
- https://static.s123-cdn-static.com/uploads/4378153/normal_60067592e6a11.pdfIn PDF document text
- https://novatoful.weebly.com/uploads/1/3/0/9/130969934/zanugo.pdfIn PDF document text
- https://woxisuxifajise.weebly.com/uploads/1/3/5/4/135400236/gekofijeguwim_raxos.pdfIn PDF document text
- https://zatitudebijozi.weebly.com/uploads/1/3/4/4/134460539/dodazi-jomoxiwinigiron-bexisepugenami-fubutizu.pdfIn PDF document text
- https://dikemogegopur.weebly.com/uploads/1/3/1/4/131406608/rexukivuj-mezadubopux-xenigidip-xerodikesijus.pdfIn PDF document text
- https://sesupukaxupasi.weebly.com/uploads/1/3/1/0/131070911/6e81d6.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4446029/normal_6003b04df3fdd.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/mexijegedakol/busonid_spray_nasal_bula.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/825a37da-6707-42e6-b0cd-478f70bc8096/25354550837.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f033aa53-c26f-4b23-8bfb-9b3b4a86f8f5/parebenogujatejefupetami.pdfIn PDF document text
- https://s3.amazonaws.com/jesidofefe/10995843211.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f0b474a5-25fe-4aff-b065-366d126369a0/c_programming_language_basics.pdfIn PDF document text
- https://s3.amazonaws.com/rebomedug/pegorixovuvofakaf.pdfIn PDF document text
- https://s3.amazonaws.com/fuwuzerijofa/23625624274.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/31c56bc7-612d-4507-983c-caa676b7e7ab/14315152080.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3f86029d-d4a8-4f15-afa0-af44260b2f64/23185918475.pdfIn PDF document text
- https://s3.amazonaws.com/loneminovu/27180211835.pdfIn PDF document text
- https://s3.amazonaws.com/zusevamasor/4166308391.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/26fd9cc0-7a64-4319-bf88-18262caa557b/riwebujevoloboz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1e8752a7-ba64-4edd-ae99-caee32a1d23d/12692613179.pdfIn PDF document text
- https://s3.amazonaws.com/dukajevo/ielts_essential_guide_reading_test_1.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e8db.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE8DB | 5224 bytes |
SHA-256: a9222d9f45f5689014296f72890609dcc9b61908f5e033bb185b5814fa6e79c6 |
|||
font_01_sfnt_off0000faa1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFAA1 | 10416 bytes |
SHA-256: 01b7ebedf88f530707b4da33307676ff679e5a5abfa2a5eb7c6c170c9148971d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.