MALICIOUS
66
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains an embedded URI pointing to a suspicious domain, identified by ClamAV as a phishing trojan. The document body, though heavily obfuscated, appears to be related to a book title, likely serving as a lure to encourage clicks on the malicious URL. No scripts were extracted, but the presence of the external URI and the ClamAV detection strongly suggest a phishing attempt.
Machine Learning
- Nyx PDF Classifier clean score 0.0642
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/award?keyword=la+casa+de+bernarda+alba+pdf+cervantes+virtual PDF link annotation
- https://cdn.sqhk.co/nokowifupe/VHBfjgF/zonifatutet.pdfIn PDF document text
- https://cdn.sqhk.co/mapuvokunoj/HD7ihjc/28638906739.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4426701/normal_602b61536b3fc.pdfIn PDF document text
- https://cdn.sqhk.co/salusasopuvi/jhgdEib/music_landing_page.pdfIn PDF document text
- https://cdn.sqhk.co/lekuruzomef/hj3wbnL/25th_amendment_in_constitution_of_pakistan.pdfIn PDF document text
- https://cdn.sqhk.co/narulaloro/eihH0L7/weapon_masters_roguelike_mod_apk.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4460460/normal_5fe61f39cbfc2.pdfIn PDF document text
- https://cdn.sqhk.co/muditazu/chdijgc/34403486058.pdfIn PDF document text
- https://cdn.sqhk.co/luwesefizi/hgshhfJ/pool_service_professionals_llc.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4376874/normal_5ff1fc5dcc5c8.pdfIn PDF document text
- http://fontawesome.iohttp://fontawesome.io/license/In PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://scripts.sil.orgThisIn PDF document text
- http://www.thdl.org/http://www.thdl.org/TibetanIn PDF document text
- http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102HussainIn PDF document text
- http://smc.org.inhttp://smc.org.inIn PDF document text
- http://www.opentle.orgIn PDF document text
- http://www.indictrans.orgIn PDF document text
- http://www.fontrix.comhttp://www.nhncorp.comIn PDF document text
- https://s3.amazonaws.com/muvarelo/understanding_business_11th_edition_ebook.pdfIn PDF document text
- https://d1159ab4-cbf5-42eb-897b-83a5e94cd7da.filesusr.com/ugd/536122_85bb143d17e34bcfa388b52af14113f9.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/sinadi/95650230985.pdfIn PDF document text
- https://a6668164-4238-4e0d-addb-cc4c62f58fca.filesusr.com/ugd/2dfcca_2f8f3674883247109057a1f4131d8d3f.pdf?index=trueIn PDF document text
- http://bazolajeruda.rf.gd/ncis_new_orleans_the_river_styx_part_ii_cast.pdfIn PDF document text
- https://37bdae34-bb2f-403f-997c-54a7c09d9c06.filesusr.com/ugd/dc98cc_e485a90da3934285aa052837da8b08db.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/kovozenamofox/bekapakebopedonaruluxezer.pdfIn PDF document text
- http://zanebinelit.rf.gd/asymptotic_form_of_airy_function.pdfIn PDF document text
- http://posidepixofonep.epizy.com/a2_reading_comprehension_practice_test.pdfIn PDF document text
- https://s3.amazonaws.com/ruzumeb/android_handler._callback_handlemessage_return_value.pdfIn PDF document text
- https://7ef5d8b8-74ac-4e0a-b0a0-fa61ca6462a8.filesusr.com/ugd/23e9be_87ec8a1d06b8410c90b05a4761e1c819.pdf?index=trueIn PDF document text
- https://025b4bf0-2906-4f5f-8a0f-6d4b68fc9518.filesusr.com/ugd/148ee2_9cb55c726cbc42b3a03e768bc7ded009.pdf?index=trueIn PDF document text
- http://nanebovovut.epizy.com/pattern_recognition_and_machine_learning_christopher_bishop_download.pdfIn PDF document text
- https://s3.amazonaws.com/mupukesunobaga/54363387821.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://scripts.sil.org/In PDF document text
- http://scripts.sil.org/OFLAbyssinicaIn PDF document text
- http://www.gnu.org/copyleft/gpl.htmlTibetanIn PDF document text
+2 more URL(s)
Extracted artifacts 15
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_014_off0006c0f8.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x6C0F8 | 36748 bytes |
SHA-256: 1bd90e5846021ffd17d668f218460c4acb9172d07250051f3b025e094e5cf416 |
|||
font_00_sfnt_off0004ba2e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4BA2E | 11560 bytes |
SHA-256: 34c2bca5824800ae193ce192efe6cf471d2e5db29a6e4d81fe896277fde81cfb |
|||
font_01_sfnt_off0004d6ae.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4D6AE | 46848 bytes |
SHA-256: 37fd932675d4a6475d231db7f7ba79754ff5acf3372dffe703cfdf8322c30af9 |
|||
font_02_sfnt_off0005653d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5653D | 1668 bytes |
SHA-256: 6c4b6e19481b0ed761bdd7505e6888df93f015d24599fd403a2c77e9c178275c |
|||
font_03_sfnt_off00056d8b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x56D8B | 5292 bytes |
SHA-256: 49d29a6cf7d60e2aa9f327bfbefaae9e8a62541371e2a977310ddfd89660062b |
|||
font_04_sfnt_off00057f59.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x57F59 | 6580 bytes |
SHA-256: 75c403a8d504a0acc9173a515bad6cbc2feda3052f7b3331721712b4588c810c |
|||
font_05_sfnt_off00058f9d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x58F9D | 22456 bytes |
SHA-256: 8fce711fedb68aba2ffcda2badc6687891184225d87f43cca99e4f3e0f42e9b1 |
|||
font_06_sfnt_off0005b3bb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5B3BB | 8688 bytes |
SHA-256: 6f19fb84c80eebc9206ffa3233f5e12a0c1aaef7f5d39160ecb7f9db5bd083ec |
|||
font_07_sfnt_off0005c4b0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5C4B0 | 2564 bytes |
SHA-256: 2dcd36784a6f37059b270d207b2728a9745b438d9ae1811e259b3f3a4d841862 |
|||
font_08_sfnt_off0005cecd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5CECD | 2864 bytes |
SHA-256: 6e7388f29f1d7ddc4d11b648e89d324b07653f52d4da819c090a6f95a96a6568 |
|||
font_09_sfnt_off0005daee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5DAEE | 6532 bytes |
SHA-256: 4e6325fd0c988876b2a064c0ea432e4333c27965154c7a6bd965791b0cf84283 |
|||
font_10_sfnt_off0005ead5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5EAD5 | 3772 bytes |
SHA-256: 56a027e0c136a199c331c60ff32fcc2e4a29ad24f8fc85650d87563801a95641 |
|||
font_11_sfnt_off0005f665.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5F665 | 77908 bytes |
SHA-256: 863ab25022ee73149e45e6960210cac566c1a8c855bb186d26c0a0481d4eadf1 |
|||
font_13_sfnt_off00070f70.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x70F70 | 2708 bytes |
SHA-256: c84f8acab3a9c5ca2adc69b236825ca6c9665d498d6e40b336d2bb841533e12c |
|||
font_14_sfnt_off00071a8c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x71A8C | 10320 bytes |
SHA-256: 97c8512466c6b874587be1a5d547db8b96786ac10c100d380b8fad136fef1175 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.