MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a heuristic indicating an external URI, specifically 'https://druttle.ru/wix?keyword=parkersburg+police+department+hiring', which is likely a phishing lure. ClamAV also detected this file as 'Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0'. The document body, though heavily obfuscated, suggests a pretext related to job hiring, aligning with phishing tactics.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/wix?keyword=parkersburg+police+department+hiring
- https://cdn-cms.f-static.net/uploads/4479925/normal_60586a44771d2.pdf
- https://static.s123-cdn-static.com/uploads/4409236/normal_6007eb1c43fc1.pdf
- https://cdn-cms.f-static.net/uploads/4416939/normal_603210172adbd.pdf
- http://swiss-family.space/nibotidajxuafn.pdf
- https://static.s123-cdn-static.com/uploads/4475738/normal_5fdde6c092d42.pdf
- https://static.s123-cdn-static.com/uploads/4402737/normal_6005ff49d5a3f.pdf
- https://static.s123-cdn-static.com/uploads/4405459/normal_5fc5e345affbe.pdf
- https://cdn.sqhk.co/dusaradezat/jcCmhfc/crypto_mining_bot_telegram.pdf
- https://cdn-cms.f-static.net/uploads/4445119/normal_600dc7d8403ee.pdf
- https://cdn.sqhk.co/gewewoturila/eCEpYMG/mateziwelefilune.pdf
- https://cdn-cms.f-static.net/uploads/4456676/normal_6018408536fb6.pdf
- https://cdn-cms.f-static.net/uploads/4489980/normal_603c14b13abb2.pdf
- http://itsnat.space/64846860620kwp4x.pdf
- http://oneplusonemain.xyz/pipe_fishmouth_templateapnvw.pdf
- https://cdn-cms.f-static.net/uploads/4481527/normal_6041adba77228.pdf
- https://cdn.sqhk.co/vofonowul/fx7jcgj/33179778513.pdf
- http://good-production11.site/canon_eos_rebel_xsi_user_manualvsy42.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/xoxaneral/99810526221.pdf
- https://uploads.strikinglycdn.com/files/bc283281-27e3-43d8-8203-f6f397eee8dd/88880940581.pdf
- https://s3.amazonaws.com/zaxefemebidaz/haunted_house_waiver_form_mckamey_manor.pdf
- https://uploads.strikinglycdn.com/files/55617fdc-3b53-42e8-84f7-0491b160b3ec/35058959215.pdf
- https://uploads.strikinglycdn.com/files/a6ad8df6-4353-485f-8f87-4fa2b3a33a6d/kenmore_elite_refrigerator_french_door_spring.pdf
- https://uploads.strikinglycdn.com/files/9171472c-84a7-482c-8421-5d6e134eb51c/sex_and_the_city_3_date_de_sortie.pdf
- https://s3.amazonaws.com/wajibile/929266382.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1a1.bin1129eed6ed5a40891c464680c58bd507172aaf0efd6a8b0c311fa8dab7a87dfc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1A1 | 5692 bytes |
font_01_sfnt_off000104ca.bin40c57ca5f7bb8029476991e7497e01067f0dac1280fcdd80da1ef81ee92310df |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x104CA | 11372 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.