MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file, disguised as a document about love poems, contains a significant number of external links, indicating a link farm or phishing attempt. The ClamAV detection and ML classifier strongly suggest malicious intent, likely to redirect users to phishing or malware-hosting sites. No scripts were extracted, but the presence of numerous external URLs is the primary indicator of malicious activity.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/aws?utm_term=love+poems+for+a+husband+from+the+heart
- https://cdn.sqhk.co/dikonutudibe/3ijZzAU/zetukimasoka.pdf
- http://smartcoin.design/grounding_exercises_for_dissociationy8wdf.pdf
- https://cdn.sqhk.co/nefikelifu/dCidjdj/99073562770.pdf
- https://cdn.sqhk.co/fetebutujo/83MMmSD/pac-_man_championship_edition_2_switch.pdf
- https://cdn.sqhk.co/wuzevunoxina/idq9Els/bugaboo_cameleon_repair_manual.pdf
- https://cdn.sqhk.co/towinomer/eghm4ia/10495409693.pdf
- https://cdn.sqhk.co/kopilixa/iibeGjf/9244950930.pdf
- https://cdn.sqhk.co/datolabevev/ijexjgM/kenigixopowubekaxes.pdf
- https://cdn.sqhk.co/pozazoji/chalnia/fevabopofavibovito.pdf
- http://vizionsmc.net/80369896818x7qoq.pdf
- http://avlto.best/sundance_spa_filter_chartkoo7i.pdf
- http://jopkapopka.online/28789308146aky79.pdf
- http://tryne.xyz/ninijirlklhj.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/8b7874a2-5a08-4b8d-b300-2dbaa703df51/which_phones_support_qi_wireless_charging.pdf
- https://uploads.strikinglycdn.com/files/9a1958da-3543-4a01-961b-f0a1ffb989a1/taking_care_of_wife_quotes.pdf
- https://d046670e-94b8-4ea2-8efc-69fca9b502c9.filesusr.com/ugd/c0b427_513c9190c37a4e7a880534d08b26ca81.pdf?index=true
- https://5d94d51b-2702-4b64-8df3-eadd022f3edc.filesusr.com/ugd/2ddd39_5a0847ab66cc40f78c7b91e861d1358c.pdf?index=true
- https://uploads.strikinglycdn.com/files/1f67ccff-96d0-4335-9a69-bc0fb43db43c/19892910893.pdf
- https://uploads.strikinglycdn.com/files/ce675966-8b8a-4f51-a0dc-aab77ffaebc0/zovikevomigopinojelozu.pdf
- https://uploads.strikinglycdn.com/files/d6ff0363-81d3-4c9f-ad4c-500bfacb0599/act_2016-17_practice_test_answers.pdf
- https://184d393c-d2ff-49e5-bbcb-48626b1dbf88.filesusr.com/ugd/49be48_d67f01147a964542af34a4c14d23f931.pdf?index=true
- https://aefbb2f1-1cfc-4a48-aab2-d72547d84173.filesusr.com/ugd/2f3ac6_1912e0b3129d4a4b8bcafe280a75c8ef.pdf?index=true
- https://uploads.strikinglycdn.com/files/6b1e2d28-480d-408e-9a33-eaf294eb34ac/xolokoboj.pdf
- https://uploads.strikinglycdn.com/files/a82472ae-2ee7-4a1c-9b08-aebee0c38f3b/88034069363.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ebb7.bine9d7d3c2ec00c5dc1e2cf4743f8927b2f58cdcf701d6fac048cb2e0cbdb862e4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEBB7 | 5392 bytes |
font_01_sfnt_off0000fde6.bin529a5e289de8cf50bf3466516aa9e197cd181350ac9510a93c45b4f6336f28a0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFDE6 | 10040 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.