MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. The heuristic PDF_SEO_LINK_FARM indicates the presence of numerous external links, with a primary example being http://worelimupuvefam.mywebcommunity.org/burger_king_specials_breakfast_menu.pdf. This suggests the document is designed to direct users to a large number of other resources, potentially for malicious purposes such as phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/aws?utm_term=dna+replication+worksheet+answers+biology+corner
- http://worelimupuvefam.mywebcommunity.org/burger_king_specials_breakfast_menu.pdf
- http://sotipidikukunow.getenjoyment.net/anatomia_e_histologia_del_cuello_uterino.pdf
- http://lorewipa.scienceontheweb.net/asarta_butters_principles_of_economics_2nd_edition.pdf
- https://static.s123-cdn-static.com/uploads/4446646/normal_5fe16d3fe4dde.pdf
- https://cdn-cms.f-static.net/uploads/4450338/normal_602af018581d0.pdf
- https://fademorojotuk.weebly.com/uploads/1/3/1/3/131379253/risusinegixawox.pdf
- https://mabamigetope.weebly.com/uploads/1/3/4/4/134493328/8052197.pdf
- https://cdn-cms.f-static.net/uploads/4420747/normal_5fd7934ee5389.pdf
- https://cdn-cms.f-static.net/uploads/4476437/normal_6046399216d47.pdf
- https://cdn-cms.f-static.net/uploads/4481168/normal_6025be1cb2fc8.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/218b712e-b984-4008-ad29-d8047bd0795b/93464723765.pdf
- https://uploads.strikinglycdn.com/files/86b0ec58-e82d-4ed6-bb3c-86b9742e0775/victorian_language_of_flowers_lily_of_the_valley.pdf
- https://s3.amazonaws.com/degagaziv/faleki.pdf
- https://uploads.strikinglycdn.com/files/f26b384a-a32a-4d1b-a2bb-4fe274635274/the_adventures_of_tom_sawyer_chapter_24_summary.pdf
- https://uploads.strikinglycdn.com/files/41c505c9-42f2-4886-9720-51b7c2be4812/2665207147.pdf
- https://s3.amazonaws.com/gezizefefififa/wolunuwibofopebix.pdf
- https://s3.amazonaws.com/jajuzasalikirut/rumepo.pdf
- https://uploads.strikinglycdn.com/files/0ba06da1-4bd8-48de-8ccd-9cf9e439bbe5/sezawajiza.pdf
- https://s3.amazonaws.com/lewuli/full_body_stretching_program.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dd9c.binc7a4d49f271e322793138594c39020030ef35f26dea9ef8d3e33a4ea7f84be66 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDD9C | 5592 bytes |
font_01_sfnt_off0000f0bf.bind1dd726bc0027462e0f61d8e6e1f9152872db5581030f9d1a67e74b4d155292b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF0BF | 10508 bytes |
font_02_sfnt_off0001150d.bind1a84ba8f0e4a827a048d387db8dd5dae3538f1c7e72415b16af587a9947cdc7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1150D | 16060 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.