MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, flagged as a link farm, suggesting a tactic to manipulate search engine results or direct users to malicious content. ClamAV and ML classifiers confirm its malicious nature, identifying it as a phishing trojan. The embedded content, though heavily obfuscated, likely serves as a lure to encourage clicks on these external URLs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/strik?utm_term=korg+m500+for+sale
- https://jamolirotiwe.weebly.com/uploads/1/3/4/6/134693152/duvefevin-zidavazo-luzivipaxipu.pdf
- https://nasupatuvijel.weebly.com/uploads/1/3/4/6/134610874/265135.pdf
- https://puxipevabama.weebly.com/uploads/1/3/4/3/134308905/3a360f49fd.pdf
- https://mewuvirinikupu.weebly.com/uploads/1/3/4/5/134505229/denorugek.pdf
- http://idclick.cash/2356981547537isc.pdf
- https://cdn.sqhk.co/sikudile/hAKAEja/jagomuxepewof.pdf
- https://cdn.sqhk.co/vudupapuj/3XpLnie/online_compiler_java_ide.pdf
- http://kejurudoji.medianewsonline.com/husky_air_scout_compressor_troubleshooting.pdf
- http://xilenemivagola.mywebcommunity.org/10935066718.pdf
- https://mumizajasaliso.weebly.com/uploads/1/3/4/5/134598274/109b3a2ef90.pdf
- http://mail-autoscout24.net/isad_g_archivesvu77b.pdf
- http://jsexj.fun/vekibadisinoralesiao4ba.pdf
- https://cdn.sqhk.co/dozirerom/hduzeie/happy_birthday_stickers_in_marathi_for_whatsapp.pdf
- http://znakomstva18x.site/vofiduo2j0.pdf
- https://cdn.sqhk.co/sazalevimit/dkhiide/download_my_talking_hank_mod_apk_terbaru.pdf
- http://normab-id.com/239014155349nb2z.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://a4346b84-4611-49ab-b113-80c9188ca613.filesusr.com/ugd/078c79_6c66f8a8843c4d0db34124032534cc43.pdf?index=true
- https://4c6480a9-ccec-4c20-853c-cc48681c44ad.filesusr.com/ugd/935adc_e45d8e186ee743ee84a0dada5b9b3f22.pdf?index=true
- https://6fc76513-a17a-4053-940d-bef108f5ea85.filesusr.com/ugd/3a5ef0_7bb5b4a847fc4ddb86b220a91162c804.pdf?index=true
- http://nabenejajoko.myartsonline.com/rodaripuxujezaxasorop.pdf
- https://0fc0baf9-b884-4fcd-968e-f93c0f938930.filesusr.com/ugd/68ec51_219a1498d621479ca741b5b1c3c6ff60.pdf?index=true
- https://bb55feb6-a0c4-48ae-8f72-aea2c45912f8.filesusr.com/ugd/b9801a_0a2036696e7c44169d16f30e9fbc019d.pdf?index=true
- https://63c5840e-267c-49ed-94d3-fc9f9d8b9c0b.filesusr.com/ugd/8c5bc8_f7c980135f6e46328a62cdd4bc849bba.pdf?index=true
- https://b354d503-40d1-4c97-84b4-bc0b16c12f35.filesusr.com/ugd/8c7d07_ff30ab914d7f4ec494825ca2b38ef14e.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d7cc.bin9bda93b2582200189e654f172618180d8e7bf8ad77b772727f9fd77d0d6c01a5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD7CC | 5320 bytes |
font_01_sfnt_off0000e9de.bin831b8ad434d5833685f792850de2803bff718b661e74c020c20f31984a02e4d9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE9DE | 11008 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.