MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains a large number of external links, a technique often used in SEO link farms to manipulate search engine rankings or to distribute malicious content. One of the extracted URLs, https://pelibifir.ru/strik?utm_term=dominos+cheese+burst+pizza+nutrition, is flagged as suspicious and likely leads to a phishing or malware distribution site. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/strik?utm_term=dominos+cheese+burst+pizza+nutrition
- https://cdn.sqhk.co/guzufaseba/GFggTif/enerpac_parts_perth.pdf
- https://zadobezaja.weebly.com/uploads/1/3/0/7/130775221/b93a0.pdf
- https://xakowuval.weebly.com/uploads/1/3/5/3/135316831/8932363.pdf
- https://cdn.sqhk.co/fogunedevare/Jgedgfd/pimexezifipojilo.pdf
- https://cdn.sqhk.co/sepexapubu/jhhlijZ/5289791574.pdf
- https://cdn.sqhk.co/kobewudojuvo/ehaijie/screen_recorder_screenshot_video_xrecorder.pdf
- https://zepukuliro.weebly.com/uploads/1/3/5/9/135964459/ximibaset_dejasesebu_vajobubul.pdf
- https://riviruzo.weebly.com/uploads/1/3/0/7/130739493/basojafop.pdf
- https://rupimobo.weebly.com/uploads/1/3/4/8/134891389/komasejonor_vasojisera_ruxebo_wozodofewem.pdf
- https://sutopudebesi.weebly.com/uploads/1/3/1/4/131438093/mimutavexedazafuweso.pdf
- https://ruwuragawani.weebly.com/uploads/1/3/4/3/134383911/f3f83bee4e3b.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://s3.amazonaws.com/fofeguj/template_kalender_jawa_2020_cdr.pdf
- https://uploads.strikinglycdn.com/files/c2b4025c-f89c-473c-b216-95ce536ac3e7/why_do_foreign_companies_list_on_nyse.pdf
- https://69f7c7ec-f776-4f8b-90c4-e8126cd531e3.filesusr.com/ugd/772020_c4413c04d95b42759d9c9f66719c2b1e.pdf?index=true
- https://s3.amazonaws.com/metakibeme/kaxepetufafewululasalobo.pdf
- https://s3.amazonaws.com/godoremitiwuja/boomer_sooner_sheet_music_piano.pdf
- https://d8acad56-eb9a-42d1-a06c-a695c5b02328.filesusr.com/ugd/0ad6c7_cf0e0b083a074415beece1e5172823c6.pdf?index=true
- https://uploads.strikinglycdn.com/files/9c3a6a80-a9c0-43f8-afa0-bbf739406ce5/31174662223.pdf
- https://uploads.strikinglycdn.com/files/53836e11-2317-44c4-a947-1a37781c5c21/punctuation_worksheet_high_school.pdf
- https://cb0920a4-0dfc-4587-8161-bd3bf883b043.filesusr.com/ugd/df391a_837f9a8a7ed24d12b2cca7c734580508.pdf?index=true
- https://uploads.strikinglycdn.com/files/84b0a7a7-8753-4c7b-ab90-3769372fe34d/walmart_black_friday_2020_ad_11_14.pdf
- https://uploads.strikinglycdn.com/files/2234dbd5-ddc6-4717-84df-950d24da5ab4/ladulixozonatewerewi.pdf
- https://s3.amazonaws.com/rizijubovapuk/why_is_my_vape_blinking_green.pdf
- https://s3.amazonaws.com/tevomenil/zokalesur.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f614.binbe72a9e540c7d82f67be97aaf4c8bd2e92f5b3046f2f8b2bd783e04c8d374b5c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF614 | 5212 bytes |
font_01_sfnt_off0001079b.bin33ac056e1f234b386e89beaae41ed2bbbda7ca32f0db5778fdd151fc3054a7a9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1079B | 11400 bytes |
font_02_sfnt_off00012e4d.bin1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12E4D | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.