MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The document body, though heavily obfuscated, contains text related to "mitigating circumstances" and the authoring application "wkhtmltopdf", suggesting a lure to a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/strik?utm_term=how+to+get+mitigating+circumstances PDF link annotation
- https://static.s123-cdn-static.com/uploads/4420906/normal_5fcf61eacc627.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4417827/normal_605283b891487.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4381085/normal_6018eee421f9e.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://s3.amazonaws.com/fajujiju/isometric_and_orthographic_drawing_worksheets.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a4a9ccf7-7e4c-4c1d-a36e-9ae8c1a6058d/mazet.pdfIn PDF document text
- https://s3.amazonaws.com/minaxigevani/96862395789.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0defccfc-f7a4-41a1-b2b0-d0023d16f38a/69082740029.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b42f8697-823d-460b-a37a-9d9cf74afc66/what_does_restrictions_b_mean_on_a_texas_drivers_license.pdfIn PDF document text
- https://s3.amazonaws.com/pibajuwi/backgammon_free_mac_os.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e7f1f478-1381-4688-925c-43870ae5c25e/how_much_does_a_medical_officer_earn.pdfIn PDF document text
- https://s3.amazonaws.com/vetamedisoz/what_is_the_youngs_modulus_of_aluminum.pdfIn PDF document text
- https://s3.amazonaws.com/voxulija/dipalomozawobixaf.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/16782674-846d-4b8a-bccb-5e5648c691a4/68986696640.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7fdcf08d-a163-41ff-bccb-4ae1229c804f/tusigoduxokigilil.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9ad66a8c-8ef6-4d64-b4eb-d4b959702c2b/tugubebegetenidivedoko.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9d635482-cbd7-46a6-945f-7eede97ce62a/4054447787.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b33ceed4-c534-4f55-9512-a6cefae7f45f/ghs_safety_data_sheet_sections.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/00a0c0aa-ed66-478c-9c20-f37ee00a4f46/xonoje.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8a15a00a-c6fe-40e9-adc9-182cd50bfc45/58192693231.pdfIn PDF document text
- https://s3.amazonaws.com/tobaziw/aarya_2_movie_ringtones_free.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1ea65251-6c04-49fe-aebb-d9a6ee77d815/the_game_changers_diet.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3d96d15e-5f3d-4b3e-b808-b73f6c9545e0/79573310500.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0cc11fdc-33a7-4782-ad12-466bc2c7db3d/can_i_send_certified_mail_from_home_usps.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e699.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE699 | 5024 bytes |
SHA-256: 1ee22f417bdd97ba0ed5b90ba279cde41464bdb6376d4dec12dbde22710f9c57 |
|||
font_01_sfnt_off0000f7a4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF7A4 | 10936 bytes |
SHA-256: 50634f1648ba92c3404debe197eb60d4a35be97ef8d9297440e5985450ccb5b1 |
|||
font_02_sfnt_off00011cf0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11CF0 | 4324 bytes |
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.