Malware Insights
The PDF document contains numerous external links, with a critical heuristic identifying a link farm and a redirector to 'https://leonvi.ru/strik?utm_term=yyy+significado+de+colores+en+la+biblia'. This URL is presented as a search result for biblical color meanings, suggesting a phishing or content-luring tactic. While no scripts were directly extracted, the presence of PDF_SEO_LINK_FARM and PDF_SEO_UTM_REDIRECTOR_LINK heuristics, along with the ML_NYX_PDF_MALICIOUS and ClamAV detections, strongly indicates malicious intent. The document body is heavily obfuscated and unreadable, but the metadata indicates it was generated by wkhtmltopdf, a tool often abused for creating malicious PDFs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9961
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/strik?utm_term=yyy+significado+de+colores+en+la+biblia PDF link annotation
- https://natorepoxikafop.weebly.com/uploads/1/3/4/3/134314237/jidawepitigir.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4498645/normal_6010ab7a44b10.pdfIn PDF document text
- https://milobixokat.weebly.com/uploads/1/3/2/8/132815045/sigujesa_dejezapevuwe.pdfIn PDF document text
- https://nuxikete.weebly.com/uploads/1/3/3/9/133997556/8523038.pdfIn PDF document text
- https://kelezisexuva.weebly.com/uploads/1/3/0/7/130739204/8122778.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4481270/normal_601065fa61968.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4414491/normal_603c004179269.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4467612/normal_6018163c53f69.pdfIn PDF document text
- https://julitigifoxa.weebly.com/uploads/1/3/4/3/134310533/8211137.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/gateme/excel_vba_worksheet_double_click.pdfIn PDF document text
- https://s3.amazonaws.com/xalasawu/transformers_cybertron_optimus_prime_toy_review.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/97049096-0eed-4cc5-a469-f104cea8d422/2012_vw_passat_repair_manual.pdfIn PDF document text
- https://s3.amazonaws.com/masevewi/fisher_and_paykel_oven_parts_perth.pdfIn PDF document text
- https://s3.amazonaws.com/votubukaxogilix/97091986214.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/22200fe6-80a5-458b-b944-6371d29f89e6/rusifosutilivigorufuzu.pdfIn PDF document text
- https://s3.amazonaws.com/gogonof/2014223267.pdfIn PDF document text
- https://s3.amazonaws.com/zarusegibitumet/game_instructions_template_word.pdfIn PDF document text
- https://s3.amazonaws.com/faluzotixupi/month_end_closing_process_in_sap.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e086b362-30be-4815-b015-0747067eec3d/what_is_a_2015_subaru_outback_worth.pdfIn PDF document text
- https://s3.amazonaws.com/kovezux/11790950057.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b6fffb82-f9fd-4033-aa0b-4069eb2b60f5/30290217153.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ee14ac2c-47f1-4279-a0c8-152843531a83/jutapetegojaxapaxovimija.pdfIn PDF document text
- https://s3.amazonaws.com/xuzed/36091908758.pdfIn PDF document text
- https://s3.amazonaws.com/lekizopiloref/miponugo.pdfIn PDF document text
- https://s3.amazonaws.com/resixexi/ark_aberration_beginners_guide.pdfIn PDF document text
- https://s3.amazonaws.com/diwitapezu/9694076539.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00013086.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13086 | 5392 bytes |
SHA-256: ddf1938f155c0d90e5b3bb17666f20ea21bf85f08ee9d327c524d5641d0d83b9 |
|||
font_01_sfnt_off000142fa.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x142FA | 14040 bytes |
SHA-256: 67cc360157e5dd8a949f05207b1e0f5891167c2c974f8d6292742ebe5eb86a31 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.