MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains heuristics indicating it is part of a link farm and uses a password-protected archive lure, suggesting it's designed to trick users into downloading further malicious content. The embedded URL `https://vilenefex.ru/award?keyword=payroll+system+pdf+file` is suspicious and likely leads to a malicious download. The ML classifier strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/award?keyword=payroll+system+pdf+file
- https://cdn-cms.f-static.net/uploads/4406516/normal_600ab46261411.pdf
- https://static.s123-cdn-static.com/uploads/4412761/normal_5fe1b32cc7887.pdf
- http://miligiwu.iblogger.org/bspt_thread_standard.pdf
- http://xodesat.22web.org/gufuzewodareku.pdf
- https://cdn-cms.f-static.net/uploads/4466175/normal_602fa05e83e65.pdf
- https://cdn-cms.f-static.net/uploads/4365563/normal_6050c605570d6.pdf
- http://xaludilurasos.iblogger.org/lemoga.pdf
- https://static.s123-cdn-static.com/uploads/4401712/normal_5ff692edbe40f.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://71bfc0c6-4bef-405a-aee6-9e9dcaab3d12.filesusr.com/ugd/708cfd_3cf697e636444c7b9bc42b85029aa6a9.pdf?index=true
- https://uploads.strikinglycdn.com/files/6b2ceaad-a63b-4a00-8944-95748fd1c971/water_supply_and_pollution_control_8th_edition.pdf
- https://eaae50f7-3b1c-4f1b-9b3c-e2a48377569d.filesusr.com/ugd/b96e41_d205957311a14058ac6ed6a5c3dd5809.pdf?index=true
- https://uploads.strikinglycdn.com/files/50b9f3b0-4bae-434d-82dc-67669d892722/polo_ralph_lauren_coupon_retailmenot.pdf
- https://uploads.strikinglycdn.com/files/2b1477ee-5131-4014-bc27-ec5766fb262d/afterlife_lyrics_future.pdf
- http://guvipum.epizy.com/forex_chart_patterns_cheat_sheet.pdf
- https://f171294f-ed7a-4884-a773-1e826a512430.filesusr.com/ugd/20d861_0a26e0078e544186b8e9d24754bc2ba0.pdf?index=true
- https://uploads.strikinglycdn.com/files/83a378f5-b845-47e6-ac52-3f82881a9667/tuwologumufevovufanisop.pdf
- https://e18e6c05-101e-4f41-9c4d-f518aea09dbb.filesusr.com/ugd/7972b3_4aa8a1668c22406a8ee258e4040edb42.pdf?index=true
- https://af18ad75-7652-4b25-b9e0-8da5fded0af1.filesusr.com/ugd/529385_4081482377c24a03b033cd6cb4ff83e4.pdf?index=true
- https://uploads.strikinglycdn.com/files/28a4c55e-62b0-4760-8cc7-f9d54a9283ca/zerawufixal.pdf
- http://jibovofafef.epizy.com/can_i_recover_my_email_password_through_facebook.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ec5e.bin1399390f0caf28ac71d01f11535bc32089ba01e48a22be45a1b1ccd9a5ec7398 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEC5E | 5288 bytes |
font_01_sfnt_off0000fe4e.bin935fe194895e66ee82e2a5dab17e7e467b4780f58525b29146ff4933e15da633 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE4E | 10716 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.