MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains an external URI pointing to a suspicious domain, likely intended to host or redirect to a malicious payload. The presence of embedded URLs further supports the phishing attack pattern, aiming to trick users into downloading further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/123?utm_term=abantwana+intonga+yakho++fakaza
- http://luminar3-download.xyz/calculus_early_transcendentals_8th_edition_solutionsie6m7.pdf
- http://verifedform.com/kabuvobodupovefejezuxuno83egw.pdf
- http://nadurejiw.22web.org/xuzivuj.pdf
- http://davufemalolaj.iblogger.org/tuxapafujulapodoxo.pdf
- http://aycotoro6.xyz/41029727297uxdav.pdf
- http://fastcreditreport.info/avengers_logo_fonta31l8.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://sezajebufixi.epizy.com/6429606652.pdf
- https://s3.amazonaws.com/pasawexawinogad/lemur_bluedriver_price.pdf
- http://dowovefedomo.epizy.com/jijavorefetofimitusogever.pdf
- https://s3.amazonaws.com/tixedujegibex/zenaf.pdf
- https://s3.amazonaws.com/tikoweravisixu/4283758571.pdf
- http://sujomux.rf.gd/analysis_of_algorithms_robert_sedgewick.pdf
- http://dikewovob.epizy.com/7489556530.pdf
- https://s3.amazonaws.com/zepifudoxapo/kodak_esp_3250_driver_is_unavailable.pdf
- https://s3.amazonaws.com/tokit/laudate_pueri_mozart_sheet_music.pdf
- http://tusajemepo.epizy.com/pride_and_prejudice_by_jane_austen_audio_book.pdf
- http://mukadepokexow.epizy.com/el_caballero_de_la_armadura_oxidada_captulo_1_resumen.pdf
- http://gofekujapi.rf.gd/vijirosurazu.pdf
- http://wonuzewidej.epizy.com/color_psychology_read_theory_answers.pdf
- http://baxadozivu.epizy.com/2025078882.pdf
- http://begosene.epizy.com/temonefalaj.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d320.bin13b8803ed1f4ad5ca7355e62fbdf836a93c192632c9d3663d23311e4773159b0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD320 | 5160 bytes |
font_01_sfnt_off0000e4e1.bin05e736cfead2915a61393bf9d12c2e5aa4b90e13fe45386e7556004caf8d441d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE4E1 | 10412 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.