MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URI pointing to a suspicious domain, and ClamAV detection confirms its malicious nature. The ML classifier also strongly indicates maliciousness. The document body, though heavily obfuscated, suggests a lure related to 'Kwikset powerbolt 2 customer service' to entice users to click the malicious link.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=kwikset+powerbolt+2+customer+service
- http://everydays.space/98219725149c44z5.pdf
- http://autobuff.xyz/24632020558u17m1.pdf
- http://amandeepsadyora.com/410325338670eq9k.pdf
- http://zhenskiizhurnal.ru/63396725438rk5dw.pdf
- http://toportt.online/ratojorezegevomed1q406.pdf
- http://navaram.online/67381347733auf6q.pdf
- http://zeropium.com/guitar_fretboard_notes_wallpapers0gl7.pdf
- http://vengriya.space/xesazilijafusejn2zxn.pdf
- http://korecos.ru/namejul1c05z.pdf
- http://kedisuli.iblogger.org/lubedovofikebepi.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://73f4d879-981c-49fe-abc7-520f36a14a84.filesusr.com/ugd/b77b08_6d996fb545a04cbaa82673c14962eab2.pdf?index=true
- http://zalupadinukoz.rf.gd/aptiom_dosage_forms.pdf
- https://uploads.strikinglycdn.com/files/acd68c18-574e-42a6-bc1f-c6f7c62c8fdf/the_cambridge_illustrated_history_of_china_2nd_edition.pdf
- https://e8dc5420-792a-4861-90db-09cfc8d8a7d1.filesusr.com/ugd/1378f5_2e6bc6a0218742e59bd481bf1d4e8e72.pdf?index=true
- https://uploads.strikinglycdn.com/files/b920386d-1e15-482e-880a-35d1ab744a44/rock_and_roll_snowman_karaoke.pdf
- https://081e7fb2-604d-424b-9b75-a58d54a71a44.filesusr.com/ugd/abd6ea_bf7a56c6b38244408ead87e5b30e87a9.pdf?index=true
- https://uploads.strikinglycdn.com/files/e9e21f85-7dca-48df-ae93-464b432aa2dc/cyberpunk_2077_day_one_patch_ps4_size.pdf
- https://uploads.strikinglycdn.com/files/dd563598-ef12-41a8-9fa8-a0745a9d507e/harry_potter_6_trailer_ita.pdf
- http://nixemamubefam.epizy.com/what_is_general_purpose_financial_statements.pdf
- https://3f5765b5-411c-4b28-96d1-a1e3b219bcee.filesusr.com/ugd/ca847e_105972ae6bfd4400845533819c6d7d97.pdf?index=true
- http://dolipefutulej.epizy.com/akshara_song_badhai_ho_badhai.pdf
- https://uploads.strikinglycdn.com/files/09548cdc-5292-4d4b-a0d3-b6df39f85521/craftsman_gt6000_lawn_mower_parts.pdf
- https://a4edf7fa-b057-49b5-8014-e5fd436fbef3.filesusr.com/ugd/c8b2c5_24f545a85cf74e02989143c06ace7617.pdf?index=true
- https://uploads.strikinglycdn.com/files/5821c206-565f-44cc-a353-a594ae99dc0e/tufinumifagimaginixemol.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eaa3.bin368c3d036d591076a03e14ba11fd10e071db23fd033d3f5b18e48d8671ec71b0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEAA3 | 5324 bytes |
font_01_sfnt_off0000fcc4.bin203bf945d121c6b12172ac55f57b643c43cfeef127af491b3df2831902598352 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFCC4 | 10052 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.