MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a significant number of external links, flagged as a 'PDF_SEO_LINK_FARM'. The primary external URL, 'https://botokaw.ru/strik?utm_term=livros+em+ingles+baratos', suggests a potential phishing or malicious redirection attempt. While no scripts were directly extracted, the heuristic 'ML_NYX_PDF_MALICIOUS' and ClamAV detection indicate a high likelihood of malicious intent, possibly involving embedded JavaScript for exploitation.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/strik?utm_term=livros+em+ingles+baratos
- https://static.s123-cdn-static.com/uploads/4411681/normal_6003aa6c550f3.pdf
- https://cdn.sqhk.co/vixukose/i2ihEgd/zibananejurozepe.pdf
- https://cdn.sqhk.co/jotapepikota/gm3dRAf/burger_king_specials_impossible_whopper.pdf
- https://cdn-cms.f-static.net/uploads/4489259/normal_6022b0e971559.pdf
- https://static.s123-cdn-static.com/uploads/4454967/normal_5fded5f3c0ee5.pdf
- https://static.s123-cdn-static.com/uploads/4446394/normal_5fc575636e4df.pdf
- http://tevutubiwij.getenjoyment.net/cards_against_humanity_cards.pdf
- http://worelimupuvefam.mywebcommunity.org/braun_thermoscan_3_high_speed_compact_ear_thermometer_reviews.pdf
- https://cdn.sqhk.co/fuxuduxexi/d0Ud9UR/pofijatesufadedelun.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://8a7e94d2-1b07-4399-8a7b-cfebf1eb419e.filesusr.com/ugd/e78b77_fceced73dbbf47f980abfeacc3067337.pdf?index=true
- https://b3e719cc-30df-460f-a5cd-d2fa480fcfac.filesusr.com/ugd/b2b6a5_68c0be425a10479a8faf36add356efb2.pdf?index=true
- https://f7f2eb1f-4ce6-40bf-b337-6bcc2c9c1a95.filesusr.com/ugd/dc6899_f0837f0615074f1b9735d55c0d596a5d.pdf?index=true
- https://7e70056c-c2aa-4e53-98c5-50750123c107.filesusr.com/ugd/f8ae5d_00b8aa5d7d3e48f5a71510b8a6423f79.pdf?index=true
- https://b01ec662-dec5-4f54-b977-8708717d6054.filesusr.com/ugd/07e02c_553530948d1d4f6e892db176e855791e.pdf?index=true
- https://6f465708-eb37-4ee2-8658-ebeec6cd93ea.filesusr.com/ugd/4bb103_e8e7d4f5f3c04d1295a4320a896e5b1b.pdf?index=true
- https://b962d5b8-8819-42e3-9ba3-d95e8366760e.filesusr.com/ugd/f51585_c2084be92cb74a5eb76d2633829c1470.pdf?index=true
- https://0aa989e7-076c-475f-bc22-fff5ae310860.filesusr.com/ugd/b44be6_ea0261dc4d344bed98c5fe7bbbdf7533.pdf?index=true
- https://3a00e800-a8eb-44ae-aafc-ae9aecab8e06.filesusr.com/ugd/1715bf_7d9987858f1643b5994e3fce82057d56.pdf?index=true
- https://070488ba-e3d9-4c74-834b-445551f5513c.filesusr.com/ugd/fb83f1_1a069bca53f94a77b7afca59bf4c4d87.pdf?index=true
- https://a179b4bb-f9e1-4b0b-8685-f881d2afde68.filesusr.com/ugd/0fdb6d_94c46e4180d742f2896c1911d98be8c2.pdf?index=true
- https://359ea524-acbf-40a7-8d58-ee96a8f10bc8.filesusr.com/ugd/ca2e76_a59dde0ecd054a4694ca2c50921ae8c5.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010259.bin666cc0db776d1fa2093bcf5043d34f9f79ef8954680994b35f45e95675fa374e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10259 | 5148 bytes |
font_01_sfnt_off000113cd.binfd255bb5748d989b9eec98b20e04fc81177643eee990f90bfa6dda392aa596a6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x113CD | 13444 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.