MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds external URLs that direct users to attacker-controlled resources. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffking.ru/aws?utm_term=asha+guidelines+ototoxicity+monitoring PDF link annotation
- https://cdn-cms.f-static.net/uploads/4389366/normal_5f96cbd0afc9b.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4368228/normal_5f87626538132.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://uploads.strikinglycdn.com/files/5ff2b499-a1a8-477e-a701-c3edbce6f942/35302822867.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/173b2027-7c43-41c0-b6e1-b62fb6ec44fe/todd_bremer_and_lawson_contact.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2a21d7dc-e03b-409a-b0ae-bb3b8d3f12ed/35132235057.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bc328b13-1ac2-47e0-b386-ef8001327b93/36825663631.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bcf90bfe-a221-4e69-b024-2f52e8de0d63/last_stand_union_city_unblocked_games_77.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f22fbcb9-f627-4a5a-bff2-297712995585/46203908110.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b6e0bc9d-c9c5-4048-971c-8410fe5d0727/vufotofiruduxis.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/079b8016-3935-4edf-baeb-16504b100402/how_to_make_a_voodoo_doll_to_control.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/09066b3f-dcd8-4a2f-ae4d-81268602f4c5/behringer_x32_producer_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/96c4f79c-287e-41ec-9a62-c9320f7d6676/63859714242.pdfIn PDF document text
- https://s3.amazonaws.com/lewuli/muwubejef.pdfIn PDF document text
- https://s3.amazonaws.com/kovilowab/robupif.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b473f46c-0c0f-4764-90f9-26c7048de1d1/tomowupuke.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7bc0e412-6550-4eac-93b9-3992c39c2fb1/92643578093.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e9ff.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE9FF | 5396 bytes |
SHA-256: 115ecc017215e26975ae7051d442508ccc924ae239812956899d3c19be6e2602 |
|||
font_01_sfnt_off0000fc28.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC28 | 10724 bytes |
SHA-256: 680ba2ce5fac0d22fd87734941628e1283fcd657e81ab7f367ae1354668f6bc8 |
|||
font_02_sfnt_off000120de.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x120DE | 4324 bytes |
SHA-256: b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.