MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://gettraff.ru/aws?utm_term=define+building+information+modelling+in+construction'. This indicates the document's primary purpose is to lure the user to a potentially harmful external site. The ML classifier and ClamAV also flagged the file as malicious, supporting this assessment.
Machine Learning
- Nyx PDF Classifier malicious score 0.8868
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/aws?utm_term=define+building+information+modelling+in+construction
- https://cdn-cms.f-static.net/uploads/4380528/normal_5fbea31834784.pdf
- https://static1.squarespace.com/static/5fc0e88b8139af0376454bd0/t/5fc1c44b2dd96f5918308b6e/1606534219956/gilogifozalodadedozikabo.pdf
- https://uploads.strikinglycdn.com/files/cd74b125-0ed8-441c-b1c8-6fdecfe6caff/udp_glotorrents._pw_6969_announ.pdf
- https://uploads.strikinglycdn.com/files/11b064a9-066e-449b-8122-05fb0e073800/bugevig.pdf
- https://uploads.strikinglycdn.com/files/33169af5-3cd3-4505-9877-94dd80c057ec/17738158944.pdf
- https://static1.squarespace.com/static/5fc0e8305687f52b6b812c21/t/5fc39e1a18e72e5fdb46da83/1606655514695/national_veterinary_associates.pdf
- https://static1.squarespace.com/static/5fc5890b084698658e7db8b9/t/5fc6c4ae0791337046ce7ea0/1606861999522/xoxogeviwiketikeger.pdf
- https://uploads.strikinglycdn.com/files/8a30aa91-d431-4618-ab40-be3d79684fdd/mumerokufajenopuwip.pdf
- https://uploads.strikinglycdn.com/files/ec7d5a91-2440-47cb-9a02-08b93b3e5f86/the_nemechek_protocol_for_autism_and.pdf
- https://static1.squarespace.com/static/5fc0e552ec917750a3d7e003/t/5fc1ac692dd96f59182dd803/1606528108676/98521585939.pdf
- https://uploads.strikinglycdn.com/files/f15b0e80-1cf3-4402-bcc1-3e8fd88a60f3/lenojiditom.pdf
- https://static1.squarespace.com/static/5fc2a81ee5c7695ca9a6fa19/t/5fc504f52dd96f59188b97f5/1606747382209/50635852383.pdf
- https://uploads.strikinglycdn.com/files/a2cd9ce0-014e-4cea-a799-9ca01ebb204d/nujajasofesiwajoroseno.pdf
Open this report in the interactive analyzer, or submit your own file for analysis.