MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains heuristics indicating embedded URLs, and one of these URLs is presented as a search result for a popular movie, likely as a lure. The ML classifier and ClamAV detection strongly suggest malicious intent, classifying it as a phishing trojan. The embedded URLs are likely used to host or redirect to further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=percy+jackson+sea+of+monsters+mp4
- http://buwovavozu.getenjoyment.net/currently_no_logon_servers_available_to_service_the_logon_request_fix.pdf
- https://cdn-cms.f-static.net/uploads/4381971/normal_6013934405a5e.pdf
- http://feyakast.online/62453599748jn27h.pdf
- http://esagafow.fun/5788305592f9ix7.pdf
- https://cdn-cms.f-static.net/uploads/4365539/normal_601c9733752b9.pdf
- https://cdn-cms.f-static.net/uploads/4425910/normal_602a97f8e8b0b.pdf
- https://static.s123-cdn-static.com/uploads/4382414/normal_60033c7873397.pdf
- http://dezowem.medianewsonline.com/archetypes_and_motifs_in_folklore_and_literature_a_handbook.pdf
- http://gewusoluxul.scienceontheweb.net/kindergarten_reading_books_free.pdf
- http://bupro.asia/ansys_apdl_ls_dyna_tutorialck3s9.pdf
- http://axecheat7.xyz/821426460696ssp5.pdf
- http://vk-settings-change.online/461066311137jx2q.pdf
- https://static.s123-cdn-static.com/uploads/4476427/normal_5fc95fd345502.pdf
- https://static.s123-cdn-static.com/uploads/4489843/normal_6000cf8c12a8b.pdf
- https://cdn-cms.f-static.net/uploads/4386336/normal_602bb4763edc6.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://f0f855fd-29d2-4bf6-9fdd-af1de8d1f91d.filesusr.com/ugd/184831_511a61edefab4b208a6acc1c52f86514.pdf?index=true
- https://ded05c8b-f0d8-42bc-a64b-daa0b63394ca.filesusr.com/ugd/99afdc_8ff4f4670c4c4eb281d1f8afdb299e6f.pdf?index=true
- https://7afd96e6-4611-46d4-9b98-d111b897c281.filesusr.com/ugd/154221_665dfbec0b8c42db82a851e684b1c436.pdf?index=true
- https://36fc1fe3-b646-4cc1-b6e9-de51469aea27.filesusr.com/ugd/3eb4bd_5fba81dde9d54ab697ca12b0842f4587.pdf?index=true
- https://s3.amazonaws.com/negonanopix/corporations_canada_annual_return_form.pdf
- https://s3.amazonaws.com/sowewazulejewi/char_broil_grill_4_burner_manual.pdf
- https://86042ffc-9b62-460b-8552-fb2522205a17.filesusr.com/ugd/4f92c1_93e31da9130e4790a1f4949f7758835f.pdf?index=true
- https://s3.amazonaws.com/xijuxosisomuna/kavotewupa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e3d5.bin46d6a7e73b072c288d41db85fabe38eaba1ea47d5cab94c87c8d986ae67cb901 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE3D5 | 5460 bytes |
font_01_sfnt_off0000f66e.bin667c2a268964db77b2782680f855ece75a19163a4dae22794933e1e80363125e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF66E | 11872 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.