MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains an embedded URI pointing to a suspicious domain, likely intended to trick the user into downloading a secondary payload. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/123?utm_term=chamma+chamma+full+video+song++1080p
- https://cdn.sqhk.co/wemitupu/jji2ogg/kuvazawugumuzogupuvolo.pdf
- http://strahauto.website/grammar_exercises_tenses5ckmm.pdf
- http://russianstravel.ru/96510025651mc9rp.pdf
- http://xelamoxadavas.mywebcommunity.org/69336760738.pdf
- http://sijemogezabusa.sportsontheweb.net/31450580138.pdf
- http://jedilinosur.mywebcommunity.org/41975938448.pdf
- http://pekibimige.mygamesonline.org/advantages_and_disadvantages_of_ambush_marketing.pdf
- https://cdn.sqhk.co/sitopizol/HV7i2hb/woborixukonisadububabowo.pdf
- http://santecmb-sarl.com/all_living_organisms_contain_what_elemento7k7i.pdf
- https://cdn.sqhk.co/tezejikibus/fjdhgih/41492974653.pdf
- http://tufodudem.mypressonline.com/astm_a572_grade_65.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/7280c8d6-edaf-4bd6-bbd2-17512454ad5c/5989474458.pdf
- https://uploads.strikinglycdn.com/files/9ca3c48a-56d3-499e-8484-d9f4c6e6f45c/how_to_get_a_jammed_vhs_out_of_a_vcr.pdf
- https://uploads.strikinglycdn.com/files/eb45142d-a529-40fc-981f-483f0c8a9eaf/how_to_get_3d_warehouse_on_sketchup_online.pdf
- https://uploads.strikinglycdn.com/files/88a09a8f-0b24-409b-a76f-6c158bbeb232/how_to_use_roku_lost_remote.pdf
- https://uploads.strikinglycdn.com/files/77b434cc-aba5-47da-ba75-a079232e0db7/5th_grade_math_vocabulary_list.pdf
- https://uploads.strikinglycdn.com/files/3b2ecf69-a49f-4ed7-a931-c39c4d0e9d05/54867354593.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e267.bin30af449b92c1d82c5666e646b9b00cf7923e7cba15b12e732b420aefc6a72f74 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE267 | 5824 bytes |
font_01_sfnt_off0000f628.bin67c08abdb82a879dd6e1425f07951507e41635ce70e8f631de5c75366752a527 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF628 | 11848 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.