MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file contains an embedded URI pointing to a suspicious domain, traffking.ru, which is flagged by heuristics as a potential phishing or malicious URL. ClamAV detection further confirms its malicious nature. The document body, though heavily obfuscated, contains text that appears to be a lure related to 'dice in spanish sentence', suggesting a phishing or social engineering attempt to redirect the user to the malicious URL.
Machine Learning
- Nyx PDF Classifier malicious score 0.6422
Heuristics 3
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffking.ru/strik?utm_term=dice+in+spanish+sentence
- https://guxesawaxogego.weebly.com/uploads/1/3/4/3/134314991/2f772d62f894d4d.pdf
- https://uploads.strikinglycdn.com/files/31796a6d-992a-40ed-9bd6-2ff5825fa8eb/ross_westerfield_jaffe_corporate_finance.pdf
- https://uploads.strikinglycdn.com/files/5b140584-ed77-4b19-9897-028cd761e384/melawinurarinupo.pdf
Open this report in the interactive analyzer, or submit your own file for analysis.