MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. An external URI was found pointing to 'https://druttle.ru/award?keyword=augusto+boal+games+for+actors+and+non+actors+pdf', which is likely a phishing or malware distribution URL. The document body, though heavily obfuscated, suggests a lure related to a document search result.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/award?keyword=augusto+boal+games+for+actors+and+non+actors+pdf
- https://static.s123-cdn-static.com/uploads/4369506/normal_5ff03cbb0a69b.pdf
- https://static.s123-cdn-static.com/uploads/4379844/normal_6009029069089.pdf
- http://coolvdomaion.online/crise_falciforme_o_que7maok.pdf
- http://muldwych.com/jexupalibibamei0xro.pdf
- https://cdn-cms.f-static.net/uploads/4465538/normal_5fd0a9b2542db.pdf
- http://kapusta.pro/33516018776vkl4h.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://7e079b21-6cfc-4bbc-a8af-001f4930a7f2.filesusr.com/ugd/f66805_71d082f9b5094d1987bdc1a939960320.pdf?index=true
- https://uploads.strikinglycdn.com/files/f6774a1b-0b94-4d0e-ae4d-6aac792932d2/18771843498.pdf
- https://uploads.strikinglycdn.com/files/aeeec689-f67d-43c1-b614-fa6f2697411a/55250938314.pdf
- https://s3.amazonaws.com/bevekizadoxuj/address_labels_template_32_per_sheet.pdf
- https://s3.amazonaws.com/wemofodi/foxtel_movies_channel_guide.pdf
- https://s3.amazonaws.com/divelatoxa/nuxokovewofuxofofas.pdf
- https://b993c520-4fc9-488d-8dda-35d8b3dc2713.filesusr.com/ugd/6f5492_3926214a466c442cbb11501dd2f9be6a.pdf?index=true
- https://c5c27394-2042-4749-9b39-d1c24dcbd9f0.filesusr.com/ugd/e9b987_b06b7b794ce24dcfac41e9f264dfb288.pdf?index=true
- https://5926284e-b61c-4ed0-95e5-27b9feedd2c3.filesusr.com/ugd/50c35f_62fd1989c7fa4d768d30501e063f0325.pdf?index=true
- https://uploads.strikinglycdn.com/files/b1b08dc1-6b53-4602-92fe-6709bc93b35c/tom_sawyer_and_huckleberry_finn_2014_english_subtitles.pdf
- https://s3.amazonaws.com/nopomewegobij/chess_puzzles_mate_in_2_free.pdf
- https://uploads.strikinglycdn.com/files/afa867e7-66bf-4899-90d0-4b86c7ccb685/2005_jeep_grand_cherokee_5.7_hemi_engine_for_sale.pdf
- https://uploads.strikinglycdn.com/files/69144942-d7c1-4006-b6ca-e64e4910ad59/matlab_legend_column_title.pdf
- https://uploads.strikinglycdn.com/files/c760c874-7e54-4a0f-b8c2-b7c38607b5d1/lukinimafanusuzadopese.pdf
- https://f4e740b0-69d0-4d5c-a0c7-362dc6b2ad6d.filesusr.com/ugd/0356fc_2f054b14007a4e6b8662021da620038f.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000106b2.bin22a7290c1327cfdcc73b05cb2689e77e98b8c6452a86fff60620d04f69af8c3d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x106B2 | 5436 bytes |
font_01_sfnt_off00011914.bin9b2253af3a83c62b8e1519820ad5acff72edc92aa887f96672dc40cecf523fe7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11914 | 10784 bytes |
font_02_sfnt_off00013d58.bin05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13D58 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.