MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by multiple heuristics, including ML and ClamAV, as malicious and phishing-related. It contains an embedded URL that redirects to a suspicious domain, likely serving as a lure for users to download further malicious content. The document body, though heavily obfuscated, suggests a 'worksheet' theme, aligning with common phishing lures.
Machine Learning
- Nyx PDF Classifier malicious score 0.9989
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/strik?utm_term=missing+angles+in+triangles+worksheet PDF link annotation
- https://cdn.sqhk.co/wujukipako/FGobRjf/warriors_cat_adventure_game.pdfIn PDF document text
- http://fixmarker.fun/34611917980umysq.pdfIn PDF document text
- https://cdn.sqhk.co/jaselavujuwi/jfgg62o/boat_bill_of_sale_form_nc.pdfIn PDF document text
- https://cdn.sqhk.co/pebekaja/gJjglW0/43978117126.pdfIn PDF document text
- http://fabermanufacture.ru/53476357764ieedk.pdfIn PDF document text
- https://cdn.sqhk.co/dimumaneda/gehejag/71581006288.pdfIn PDF document text
- https://cdn.sqhk.co/nozelenid/OuKdYgd/rebemimivuxemejanigalosi.pdfIn PDF document text
- https://cdn.sqhk.co/gonolesuzam/hjaGicv/juvakijusumegasuluzup.pdfIn PDF document text
- https://cdn.sqhk.co/jasorevujoxu/iagcoib/internet_manager_6._35_build_3_crack.pdfIn PDF document text
- https://cdn.sqhk.co/wugunifikezu/didifgc/wolf_3d_model_rigged_free.pdfIn PDF document text
- https://cdn.sqhk.co/vulovosovem/jd3xhaR/pac_man_world_game_boy_advance.pdfIn PDF document text
- https://cdn.sqhk.co/nopawuwam/ijIMic9/25116107475.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/c1d64b05-485d-448d-94b6-2e1cab30fb9b/87245344232.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/25c0003b-ea1d-45d7-ace0-0eb6bc2ddb70/movizagabizukibibib.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/16e9e316-0216-41ef-95cb-63e6556fe328/different_types_of_poetry_ppt_ks2.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f233c9eb-b513-48f9-83db-3dfece58999b/evinrude_18_hp_fastwin_gear_oil.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ab9af7ae-30b8-4a93-8711-54c5b1d250e6/ragupoxebivariluxotes.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dde7571b-4886-4cae-b76c-77c4ea4762cb/19110226755.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/30b811c1-a57c-4fdb-b000-c5b4ec024353/xovimedagatudu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cdc5c458-3145-46f3-92a5-829f24fdafe4/61778117194.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7f42f0b2-f790-4e63-8b35-16551010ba66/73095891397.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/08bfb270-05e3-469a-85fb-9d8baa23569c/a_simple_favor_review_nytimes.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ff64fcb5-e115-4afa-91a3-7988e628d487/dilawawem.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/64d0c96c-91ea-4f5b-a76b-375273d9f422/craftsman_snowblower_manual_model_536.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c473f6dd-c457-4e88-89c5-b29e4fe38b55/the_picture_of_dorian_gray_movie_watch_online.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001017d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1017D | 5108 bytes |
SHA-256: 406ce291ae0671743d8d4e3978b728e1ddcf5ac6cb0f67a73781164fcaafa837 |
|||
font_01_sfnt_off000112f3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x112F3 | 10832 bytes |
SHA-256: 228e190a2c75842aee34be3d8c4bbdf9ed9e96c784fc8e2c657663df7aaed7b9 |
|||
font_02_sfnt_off00013835.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13835 | 16208 bytes |
SHA-256: d678301a846f919a53233fa2dad1f185547c1ce6335b00ba9ee0d80b579a0c10 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.