MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and ML classifiers indicated a high probability of maliciousness. The document body, though partially corrupted, contains text suggesting a lure related to "China gate hd video song". Crucially, the PDF contains a large number of external links, with one heuristic specifically identifying a "PDF_SEO_LINK_FARM". This indicates a likely attempt to direct users to malicious or compromised websites, potentially for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://golowaki.ru/123?utm_term=china+gate+hd+video+song
- https://cdn-cms.f-static.net/uploads/4475571/normal_5fd9cb70893b7.pdf
- https://cdn-cms.f-static.net/uploads/4424692/normal_60301fa7b8945.pdf
- https://cdn-cms.f-static.net/uploads/4424666/normal_60387cb46ed83.pdf
- https://cdn-cms.f-static.net/uploads/4445340/normal_60301b4a6b0d6.pdf
- https://cdn-cms.f-static.net/uploads/4369654/normal_601d2cdf3ccd1.pdf
- https://cdn-cms.f-static.net/uploads/4480580/normal_6053ea9113a0d.pdf
- https://cdn-cms.f-static.net/uploads/4467277/normal_602609aca89d0.pdf
- https://cdn-cms.f-static.net/uploads/4374703/normal_600b77b2109d5.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://d427386d-3434-45d9-8802-370857a594f4.filesusr.com/ugd/accd1f_a84957c50d934c6f9e3757af46e36792.pdf?index=true
- https://03ca3561-abfe-48ca-9b59-b1b2b77f8126.filesusr.com/ugd/1af49e_ed4250818d13438aa4ec8e20887a3233.pdf?index=true
- https://748f1d53-d141-46c1-926a-d14fc69713a3.filesusr.com/ugd/e3ed1f_36649f1b2e9740438f27ee24779edbfc.pdf?index=true
- https://14864a69-2465-45da-a912-c6f78a3f99b9.filesusr.com/ugd/409ca8_995cccc3dbe5461b9d3164070fe35f26.pdf?index=true
- https://36622f5a-5a1b-41a5-aa98-965156e47ac2.filesusr.com/ugd/804ff6_1a3c8c18c73443689c36911fc2354c20.pdf?index=true
- https://s3.amazonaws.com/xalasawu/26416334387.pdf
- https://s3.amazonaws.com/mesixadelomomo/78546271995.pdf
- https://00c0516a-c822-4344-a779-6f74e039753d.filesusr.com/ugd/9e41f0_2fda4c8e66d341d08c978e5f7b2f10a0.pdf?index=true
- https://s3.amazonaws.com/kosipefojaw/lasixesikazokilexer.pdf
- https://s3.amazonaws.com/joterige/does_logitech_mk320_work_with_windows_10.pdf
- https://s3.amazonaws.com/fifomi/vupodiforeriwalijopategag.pdf
- https://254a6a59-343e-4b7e-907c-c4819e171fff.filesusr.com/ugd/decf6f_8b558de2fa3844eaa29ce3f568a044fe.pdf?index=true
- https://03f57db0-fbcf-46ec-8713-21b5992b8512.filesusr.com/ugd/455f95_300439e6830a420eb0628ab8c825a415.pdf?index=true
- https://s3.amazonaws.com/zowibatev/element_32_inch_smart_tv_reviews.pdf
- https://4c6480a9-ccec-4c20-853c-cc48681c44ad.filesusr.com/ugd/935adc_8f80b7f7f7db4f1ba909bb4fd352404a.pdf?index=true
- https://s3.amazonaws.com/zarevizebi/besuwipuxe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000108f4.bine35e112fed964de991defdbf92768f90e48c28aaa3f58a523da1086afc429f03 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x108F4 | 4924 bytes |
font_01_sfnt_off000119b5.bin6401ede01a3d9eb3ef3b318a8ab6e23d697b188bd36691e1a9f3f9f94d50ab37 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x119B5 | 10680 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.