MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains an embedded URI pointing to 'trafftec.ru', which is likely the destination for a phishing or malware download attempt. The document body, though heavily obfuscated, suggests a lure related to an 'emotions worksheet for adults'. No scripts were extracted, but the presence of external URIs and the malware detection strongly indicate a malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafftec.ru/aws?utm_term=emotions+worksheet+for+adults PDF link annotation
- https://cdn-cms.f-static.net/uploads/4366952/normal_5f8dd5901d5ac.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4415065/normal_5f9a88926a59e.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/de6cafd4-ab1d-4733-bb44-da0fd171cd12/90077421217.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/621e05d7-1f82-400b-ab8c-eddaa3167484/great_gatsby_study_guide.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/499bd11d-cda3-48ac-b698-18d54da27d6f/arcgis_tutorial_data_for_desktop_10._6.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e478a0fe-2d7e-46f4-ba3d-da45d3aaeee4/14845533961.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/99b51a32-a103-44f0-ba33-ce5a49a0577f/love_unleashed_dog_daycare_and_boarding.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4009af0a-c08f-4d91-8333-1612352a1f65/assassins_creed_odyssey_manual_save.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4470b680-9cdd-4fad-a1b7-3010152b9dcd/alienware_windows_8_iso_download.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/17099e40-138c-423d-942f-bcdf488885d9/kasodemonabenuwidukakux.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8407439b-9dd1-4833-a6e7-140b46ee979b/discovering_computers_2017_shelly_cashman.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e4f159b1-4854-4596-9bf8-b4ac2425c76c/suwatodarud.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bda824b2-2304-4b7b-9905-0b6f4e7c4254/71079355032.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5d34c0ae-6be3-4dde-8ba5-805aacdf78ae/63141864863.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f895f326-6494-472d-9819-0260b5055518/50920173171.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00014170.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14170 | 5260 bytes |
SHA-256: a9562bfedca479ffb1516b02fd43e54f2badd0b696b2af5db8dddf56d8bc54e2 |
|||
font_01_sfnt_off0001533c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1533C | 11144 bytes |
SHA-256: b7364f5277386c9c0bbee3ea0f0881790a6309b0493b504546050fc4049715a8 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.