MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF document that contains an embedded URL designed to trick the user into visiting a malicious site. ClamAV detected this as Pdf.Phishing.Trojan, and an ML classifier also flagged it as malicious. The embedded URL, https://druttle.ru/award?keyword=how+to+convert+jpg+file+to+pdf+in+mobile, is likely part of a phishing or malware distribution scheme.
Machine Learning
- Nyx PDF Classifier malicious score 0.9936
Heuristics 3
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/award?keyword=how+to+convert+jpg+file+to+pdf+in+mobile PDF link annotation
- https://cdn.sqhk.co/vulovosovem/33Hjdhf/9476172638.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4373004/normal_6027e0448dcf3.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4383804/normal_5fe8c75c9c3af.pdfIn PDF document text
- http://juguzixuvuw.iblogger.org/61590113494.pdfIn PDF document text
- http://tojokepolosuku.iblogger.org/lulu_support_guide_s9.pdfIn PDF document text
- https://cdn.sqhk.co/xefilelo/gijjdhe/juwuwumevaratirabura.pdfIn PDF document text
- http://pushbiz.fun/sedezogatulawowenixr6z0q.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4401555/normal_5fe5e2804a659.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://zukevajisuw.rf.gd/employee_evaluation_templates_free.pdfIn PDF document text
- https://s3.amazonaws.com/kifutizijebuj/52692838741.pdfIn PDF document text
- https://s3.amazonaws.com/gumagabu/10076125139.pdfIn PDF document text
- https://s3.amazonaws.com/xotomisen/ronesomiweserop.pdfIn PDF document text
- https://s3.amazonaws.com/zabevog/bkav_home_2018_free.pdfIn PDF document text
- https://s3.amazonaws.com/nuselufuzo/bolacha_de_arroz_camil_informao_nutricional.pdfIn PDF document text
- https://s3.amazonaws.com/bamepofewalada/56812639871.pdfIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dd36.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDD36 | 5204 bytes |
SHA-256: 52167dab794adb0a6096f9f22f82582d930be40d9a3164a948b7f4ec731d3209 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.