MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file was detected by ClamAV as Pdf.Phishing.Trojan and ML classifiers indicated a high probability of maliciousness. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document attempts to trick the user into opening a password-protected archive, likely containing a malicious payload. The embedded URL 'https://trafffi.ru/strik?utm_term=patrol+base+operations+fm' is a strong indicator of a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafffi.ru/strik?utm_term=patrol+base+operations+fm PDF link annotation
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/sizadagazagaj/business_process_management_journal_author_guidelines.pdfIn PDF document text
- https://s3.amazonaws.com/vitelitubovuluj/womobawugugoxuvuv.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ea5dc00e-0f7a-4050-b540-9b23026a31b2/81686972574.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7365a9a7-6e98-4975-acea-44210668f9ad/54636518011.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc1ae0cab79f442f22f189a/t/5fcd8fd01e1a4d7de14449d2/1607307219657/70976714135.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/14a56c5b-ed36-4858-bce2-13ac3365a5fa/jebolubiganemugomobof.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b1280d26-6619-4eed-b6b4-d871fe8efd51/jordan_peele_candyman.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6bc3ed26-f40e-4d05-bb3a-5f75801b9285/opnavinst_5530.14_navy_physical_security_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6f5bb31e-bd4f-45bb-b464-1687b74590f1/89494625171.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc0bdc717e7202640e9644a/t/5fc17ad0173fb5383bdac30d/1606515410401/monsters_inc_cda_scene.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fd12211e-4eca-4a1a-bf39-f9fdd7a56828/the_cosmic_doctrine_by_dion_fortune.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f959f5f3-9eb2-4556-b5bb-c032a9b3cefe/golazeripesilawijitilek.pdfIn PDF document text
- https://s3.amazonaws.com/temujonuwu/birds_of_prey_cast_2020.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b1309c62-6e80-4b68-a10f-a2f2db540c4c/64410894687.pdfIn PDF document text
- https://s3.amazonaws.com/tesodagiwor/4532984367.pdfIn PDF document text
- https://s3.amazonaws.com/xoguwavosuje/customer_feedback_form_html_template.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001481f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1481F | 5188 bytes |
SHA-256: 21dbf2739ea527149d72c18e24c62782e0897d6f3359f7cfdc25021d4e70e9a6 |
|||
font_01_sfnt_off000159ad.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x159AD | 11052 bytes |
SHA-256: 6b01d7289fa3f112e7b8f408099e04d3215dc6d7d6f262fdcf3a706d2cc25ed9 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.