MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://cctraff.ru/strik?utm_term=escape+game+50+rooms+2+level+24+erklarung'. This URL is likely used to redirect the user to a phishing or malware distribution site. The ML classifier also strongly indicated maliciousness, and ClamAV detected it as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cctraff.ru/strik?utm_term=escape+game+50+rooms+2+level+24+erklarung In PDF document text
- https://cdn.sqhk.co/wupifufexix/hbiawgh/ziteguzinawotifelunom.pdfIn PDF document text
- https://cdn.sqhk.co/kupovite/hH3fjev/35679052223.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/0f281d85-b4df-4f30-bdef-9e75cceaca16/jelogabiwokumup.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/669b9ac9-af68-4194-8b3e-cb9eaec923e6/flying_mounts_pixelmon.pdfIn PDF document text
- https://s3.amazonaws.com/sabegokek/dugakewuladepa.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a53a990f-40c1-42a9-a6f6-5b2fe5078e8c/85429064444.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dd7b77f4-16bc-42ba-9533-23436794693e/ziweluja.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4aff293a-7942-411e-bcd5-19bb4f09a7ff/58649316981.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c01bc548-61ae-4b03-814f-2f70f4b4c2d4/insurgent_full_movie_free_online.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e6b1daf7-670f-47db-8e65-0e2300a9bc01/fullerton_ne_dmv_hours.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6033fe79-a7f7-4b3f-8ff3-e971aa5ce507/mutonuvidedijaxufiberot.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/87a4619d-835a-4609-983f-0fda8771408c/suntrust_fraud_department.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fbe1252f-f84f-4b99-9cc7-3c81832c9a6c/71253185187.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c92f0a25-df91-4d76-8bce-c74cc6469f18/vitalina_wilson_fresno_ca.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/83ad714c-d2fa-43a0-bbf9-a6198827294a/59333569153.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1f8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1F8 | 5820 bytes |
SHA-256: 441302b6ab334f2a8bc173cf9ac4b8881722d62b40112c8d8cdb919ff9ec1978 |
|||
font_01_sfnt_off000105d4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x105D4 | 10428 bytes |
SHA-256: ebb704cc2bf6ad8070a36447d976a2f5645518e6e3ab9280c5507f4a64cc2bff |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.