MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, likely intended to redirect the user to a malicious site. The document body, though heavily obfuscated, suggests a lure related to academic homework answers, a common tactic for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/aws?utm_term=chapter+1+aplia+homework+answers+philosophy
- http://custits.space/how_to_write_a_short_response_for_job_applicationmbl9j.pdf
- http://goldenframecollision.com/14114380889tp59r.pdf
- http://idealicagocce.site/que_es_un_estilo_de_vida_occidentalr7jvr.pdf
- http://svoydvalend.xyz/20478859121lamke.pdf
- http://creditscoretracking.info/spanish_preterite_and_imperfect_practice_paragraph8ly8f.pdf
- http://fajujefa.getenjoyment.net/1st_grade_math_worksheets_word_problems.pdf
- http://gupirigugorixuf.sportsontheweb.net/la_campanella_guitar.pdf
- http://janafan.scienceontheweb.net/mange_dog_shampoo_near_me.pdf
- http://normal-id.com/chiavenato_administrao_financeirahxcne.pdf
- http://jixewelo.scienceontheweb.net/52246577356.pdf
- http://vuzomubanaj.22web.org/english_grammar_articles_examples.pdf
- http://leyloften.online/95457581628u7ks2.pdf
- http://garirixis.22web.org/ravujovixofififunimaf.pdf
- http://sfr-webmail.com/8916089327uupws.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://katiwepu.rf.gd/bateria_automotriz_funcionamiento.pdf
- http://nozozuwovore.atwebpages.com/87065400289.pdf
- http://wujagenak.atwebpages.com/attachment_theory_by_john_bowlby.pdf
- http://vujipopeb.rf.gd/bitdefender_free_crack.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011750.bine380a212a56d72a5e39b428ecf7707cee4f817449099b300f44f2334fc5bdf61 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11750 | 5276 bytes |
font_01_sfnt_off00012929.binf27570508f3726a7190ccdda4524929f86e79c3884ecbfb58d7ce78a94e53541 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12929 | 10640 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.