MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file was detected as malicious by ClamAV and an ML classifier. It contains an embedded URI pointing to a suspicious domain, which is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to 'Blackbird fly chapter 1 summary'. No scripts were extracted, but the presence of external URIs and the malicious verdict indicate it likely serves as a dropper or phishing lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.6098
Heuristics 3
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafftec.ru/wb?keyword=blackbird%20fly%20chapter%201%20summary PDF link annotation
- https://cdn.sqhk.co/wezopexa/fhjjghb/3763319104.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4415770/normal_5fa528e180163.pdfIn PDF document text
- https://cdn.sqhk.co/lapitobexeva/PDIKUhg/comicsgate_is_winning.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4394068/normal_5fe854e3d6675.pdfIn PDF document text
- https://cdn.sqhk.co/nufanusiki/hcmUPij/ratemigebu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2cfc493b-d9dc-4428-9cc8-fa7c8ba73e5f/componentes_del_espacio_geografico_naturales.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1dad3c71-f1d0-49c8-9393-4959f9395679/54165366914.pdfIn PDF document text
- https://s3.amazonaws.com/baxekojojexusol/algebra_1_regents_august_2019_answers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2a537c16-6be3-4538-b1eb-e7c4d1642cbd/19041479483.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c98c7982-88d0-463d-b3c3-e6e796c31fd3/70842940280.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.