MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, specifically identified as a phishing trojan. It contains an embedded URI pointing to a suspicious domain, 'trafffi.ru', which is likely used to host a malicious payload or phishing page. The document body, though partially garbled, suggests a lure related to a 'Guide to Lisbon'. No scripts were extracted, but the presence of an external URI in a malicious PDF strongly indicates an attempt to redirect the user to a harmful site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafffi.ru/strik?utm_term=guia+lisboa+en+3+dias PDF link annotation
- https://zudovizu.weebly.com/uploads/1/3/4/3/134338339/zojipefus-siviso.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4483591/normal_5fac1e0c6fdce.pdfIn PDF document text
- https://sijevunima.weebly.com/uploads/1/3/1/8/131859613/58954.pdfIn PDF document text
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/fibawubaxavuvabu.pdfIn PDF document text
- https://fodibiwowi.weebly.com/uploads/1/3/4/4/134479135/dikedoxamida.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4393506/normal_5fb34f4c57bab.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/7fc445f4-a145-4464-b8b1-c374a2c04dfb/catalizador_en_ingles.pdfIn PDF document text
- https://s3.amazonaws.com/bubeto/17137033277.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5ba4daee-a745-4635-971b-8ea63d6c2d6d/viridolagazeratitanem.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d98a4f93-2c5d-411c-95f6-4ccebcbe0a7f/98153705593.pdfIn PDF document text
- https://s3.amazonaws.com/salade/bhagavad_gita_yatharoop_hindi_free_download.pdfIn PDF document text
- https://s3.amazonaws.com/subud/antimanual_de_filosofia_onfray.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c98a3bf7-d7d1-4a5f-82a6-9911c9e7b2e2/deduvevugasapo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/08cf2ed0-6a7f-4eb9-b521-47127477b496/binorogumosajisawate.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/700a6338-d602-4456-940f-5c5ebd98759e/vasuropuro.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ee1f772d-6207-4d07-964d-0af22d618b72/harrius_potter_et_philosophi_lapis.pdfIn PDF document text
- https://s3.amazonaws.com/jodabiladezot/bapetobipuwe.pdfIn PDF document text
- https://s3.amazonaws.com/rogugagatuf/itinerary_template_pages.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ce07.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCE07 | 5060 bytes |
SHA-256: 166699656628f3e78ef584fe717b2f250c5fdb0dc395c8629095a36e3d7e74e8 |
|||
font_01_sfnt_off0000df4c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDF4C | 11956 bytes |
SHA-256: 10da9578912327ecf77792a01eeb119ad58be9cbc3fdf08713f35626a700a6d2 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.