MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains an embedded URL that directs users to a suspicious domain, likely for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate malicious intent. The document body, though heavily obfuscated, contains text related to 'Wii u roms wup', suggesting a lure for potentially illicit content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://crysiq.ru/pbw?utm_term=wii+u+roms+wup PDF link annotation
- https://cdn-cms.f-static.net/uploads/4391317/normal_6029a72e3d06d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4476273/normal_60b9e439d3486.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4478438/normal_60694f9d0ac35.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4446388/normal_60682450e2d8c.pdfIn PDF document text
- https://static.s123-cdn-static-d.com/uploads/4477147/normal_60b0b7146c53e.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/f5cb9aeb-6f53-4278-a318-8c77b71e307e/juxir.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d4eabfb0-4fda-49ee-a31b-6cfe8654d1d7/troy-bilt_tb110_air_filter_lowes.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b1d704ae-60bc-4ac6-a8b2-bc8f25129a3b/66443946706.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/86d8c326-aa57-491c-91f5-1e9e5957a0db/reading_comprehension_worksheets_2nd_grade.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4d367a45-039e-42c2-8d46-bc4368ac8f37/tiwawularetubavijusovejuz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/991fd37e-a279-400d-9e47-f36550581b44/bovakosan.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4d9e47f0-ab96-40e3-aa61-b26f3766063c/whirlpool_duet_sport_washer_f21_error_code.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e64d00a1-8a98-45ba-b38b-a81d40b2448f/what_size_belt_goes_on_a_craftsman_lt2000.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/93b679a5-b414-411d-b0ea-1a10e3938331/how_to_make_ladder_runewords_in_single_player.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9213c8a5-f3fb-453c-9f6a-83c86c2fbe3c/vojovelazuji.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0a5aa9b3-dd01-4518-8dc2-773c1049669e/tutatijurakupuwep.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/789d17da-a0d6-4b29-8d4d-d30608bb3b56/bisuwote.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/248454c3-9927-48c2-a792-1d04d62019b6/dogij.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d484e12f-f2e5-489c-8476-3107cdd3b708/evicted_book_club_questions.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4ad15af6-1444-4e85-b7a9-d8fa604467f5/rich_dad_poor_dad_free_audio.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/41d0f486-f12d-4c67-9359-1743ebe209ce/dixilatenasivig.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000122ed.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x122ED | 4828 bytes |
SHA-256: e8e773782779dfe75a6e79a15a8e354558b4527f775fb70a8f0354f288299e8f |
|||
font_01_sfnt_off0001335b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1335B | 12064 bytes |
SHA-256: e58722cffe085068df2ef7b43a64fb51ea012e7d7f42074c3a99bb9776679714 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.