MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file is identified as malicious by ML classifiers and ClamAV, with a high risk score. It contains embedded URLs pointing to potentially malicious PDF files, suggesting it is part of a phishing campaign. The document body, though heavily obfuscated, indicates a lure related to 'expense sheet format free', aligning with phishing tactics.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://travels-ukraine.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c12aa04661---33597272527.pdf
- https://mattweidnerlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606c8fc593f91---wabijuxiwo.pdf
- http://bubblesoflove.net/wp-content/plugins/formcraft/file-upload/server/content/files/160838830bbd33---tododaneloxasejitum.pdf
- http://www.patricktennis.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607d11e48134e---50382688670.pdf
- https://aimhc.com/userfiles/file/28177327156.pdf
- http://www.kmclogistics.com/wp-content/plugins/super-forms/uploads/php/files/5d27740d6f6506e8e4b945e935b49eee/tawadadixom.pdf
- http://www.nbrownies.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1606d2ced1dfd2---39272578665.pdf
- https://www.lowdoc-loans.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/160740326c8821---jetezifinat.pdf
- https://cal.lighting/wp-content/plugins/super-forms/uploads/php/files/2e1b968b9a14a68d3002375f6227abfe/dijusubil.pdf
- http://www.viksexteriors.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc66a2f82e---55027436462.pdf
- https://markzone.az/wp-content/plugins/super-forms/uploads/php/files/jiip6u3cnh0oc9lqhbgliq42sg/tuvujanugasatasoropowowug.pdf
- https://www.colegiodesafio.net/home/wp-content/plugins/formcraft/file-upload/server/content/files/160817e84243a8---zebuvezorusepulexovulog.pdf
- https://www.lipfish.no/wp-content/plugins/formcraft/file-upload/server/content/files/16093387ee120e---55433433356.pdf
- https://www.pharmaright.ca/wp-content/plugins/super-forms/uploads/php/files/4imhlh5ueuk8je5jouck97lktq/suvilejobumegugubupux.pdf
- https://www.a2zmedical.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16073a6c8b6058---vebot.pdf
- https://amartzon.store/wp-content/plugins/super-forms/uploads/php/files/c07dd4b1af23d278e244d2141e0ae38b/53716453820.pdf
- https://eandjfamilyhealthcenter.com/wp-content/plugins/super-forms/uploads/php/files/87992ad5e0dc70e95e166e0cd7fca9e6/bitelixazikojuzuxadelisar.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://feedproxy.google.com/~r/Uplcv/~3/Om9ozkHLxGw/uplcv?utm_term=expense+sheet+format+free
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cd93.bin3b4bee4484407e9a3863c36b7732e726076d0cd7ff77bc64b0e2df2d11f3fd8f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCD93 | 5136 bytes |
font_01_sfnt_off0000dee5.bin2f85c03853799f4f3b9d2a9c87e02858266620fa635319925d838bb54043153f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDEE5 | 10396 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.