MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a link to a known malicious redirector, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection further support its malicious nature. The document body, though heavily obfuscated, suggests a lure related to an encyclopedia PDF, likely to trick users into clicking the malicious link.
Machine Learning
- Nyx PDF Classifier malicious score 0.9544
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/strik?utm_term=godwin%2527+s+cabalistic+encyclopedia+pdf
- https://cdn-cms.f-static.net/uploads/4383147/normal_5f9816b71c253.pdf
- https://cdn-cms.f-static.net/uploads/4450421/normal_5fa000d78c9e2.pdf
- https://cdn-cms.f-static.net/uploads/4453334/normal_5fa054da0fdb8.pdf
- https://cdn-cms.f-static.net/uploads/4412899/normal_5f9f8fb289be1.pdf
- https://cdn-cms.f-static.net/uploads/4412761/normal_5f99d29777b7d.pdf
- https://cdn-cms.f-static.net/uploads/4375708/normal_5f8e350a2d3c3.pdf
- https://cdn-cms.f-static.net/uploads/4446499/normal_5fa5b78bd9643.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/pusori/mituvewiredo.pdf
- https://s3.amazonaws.com/sojaxub/borapaw.pdf
- https://uploads.strikinglycdn.com/files/ef2d9e9b-4097-483e-84db-be71666ed6da/google_developer_android_training.pdf
- https://s3.amazonaws.com/susopuzupure/kijata.pdf
- https://uploads.strikinglycdn.com/files/3d407e96-057d-4efc-807c-8fe45d28d23d/80433187695.pdf
- https://s3.amazonaws.com/jamokaroxoj/30112025624.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000b7ba.bin7df2207d2d7653d42a3bb68b7429d11f8f5437f9805b59243ae9e7395f565453 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB7BA | 5452 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.