MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a link to a known malicious redirector, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The ML classifier also flagged this PDF with a high score, and ClamAV detected it as Pdf.Phishing.Trojan. The document body, though heavily obfuscated, contains text related to 'Trb 2020 call for papers', suggesting a phishing lure. No scripts were extracted, but the presence of malicious URLs indicates an attempt to redirect the user to a harmful site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cctraff.ru/123?utm_term=trb+2020+call+for+papers In PDF document text
- https://cdn-cms.f-static.net/uploads/4445735/normal_5fa2074bbdf2c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4471109/normal_5fa40709d7728.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/aebe5e1d-36c0-4625-8d65-f31137add68b/city_politics_9th_edition.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c77ad018-0e18-42ea-822f-39a1e2cfca5a/99410047981.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/09dd6d55-ff99-4ab0-bb03-f7de88024c7f/13037416207.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/89343ddf-9885-4ab6-8278-816c2b69e5b2/bibiliya_yera_mu_kirundi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/603a036c-8e44-4625-8c06-1db3b7c35f80/saroluwusofumetelidenarul.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0bd1ec0a-bd99-42a4-9a1a-573a42f1648c/ya_no_soy_esclavo_del_temor_twice_letra.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b9749671-97d2-4a81-91c1-5ffcb7573cf9/fazapagodexoli.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bfb74281-175e-4933-99eb-ffabd58085d4/seteledulegopefalegu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bb839122-3197-4c5e-bc7c-1ec9fd58b944/happy_pet_story_hack.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4426d950-83a2-4156-8671-cbd4f41291c4/libro_administracion_de_sueldos_y_salarios_agustin_reyes_ponce.pdfIn PDF document text
- https://s3.amazonaws.com/kavitokolezub/pathology_of_cardiovascular_disease.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/30ee36dc-2bc2-40ee-bba5-1d423dda5977/pelawibalofepo.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000def3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDEF3 | 5372 bytes |
SHA-256: 2d2f2691d5d18bd508f3c2c572db5afe4d59d6d651dcc25935a231353776b32f |
|||
font_01_sfnt_off0000f145.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF145 | 10692 bytes |
SHA-256: efac45a4f3c1ebcd4a100472b16a9a2fd28079e24121e5fbcbf1886fe5192d14 |
|||
font_02_sfnt_off000115ed.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x115ED | 16060 bytes |
SHA-256: 5b0d2701ab39d2f69c66d7d16c60d8db0b323aa0832947137e757b5401d27330 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.