MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is a PDF that contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection and ML classifier also flag this file as malicious, specifically as a phishing trojan. The presence of numerous unknown-reputation URLs suggests a coordinated effort to redirect users to potentially harmful content, likely for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/award?keyword=anabasis+greek+pdf
- https://cdn.sqhk.co/lijuwezasip/cgegdxo/71997090294.pdf
- http://apsdd54gfv.xyz/how_to_reset_maintenance_light_on_2014_prius_ve0hou.pdf
- https://bobugebajagon.weebly.com/uploads/1/3/4/6/134682349/ed0fea051cec764.pdf
- http://alex-chekalev.com/4421587775126ddv.pdf
- https://sijudunewofas.weebly.com/uploads/1/3/4/6/134696620/zirosojiko_rulal.pdf
- http://bio-ita.fun/jotawipugesenufo99mkd.pdf
- http://persequen.com/sheltered_workshop_porterville_californiaqdc9v.pdf
- http://it50off.pro/texotasavurinugobarelajak8ez3.pdf
- https://kasezikibojeg.weebly.com/uploads/1/3/1/8/131871727/2141618.pdf
- http://com-signto5.xyz/55885168294gwl34.pdf
- https://zojufagilazit.weebly.com/uploads/1/3/0/9/130969654/vabusimefuzu.pdf
- http://prequester.online/parches_chenille_personalizados_parag3u4z.pdf
- http://mini-cam1.club/real_followers_pro_apk_latest_version4eyqo.pdf
- https://midigoxu.weebly.com/uploads/1/3/4/0/134000126/5755902.pdf
- https://tinabatof.weebly.com/uploads/1/3/0/7/130776088/bazanebakojezeva.pdf
- https://cdn.sqhk.co/suwapipejob/igicggf/95651998065.pdf
- http://winoorama.website/ferokitirejoztu4je.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://61249681-e2d1-4375-841a-b3723294d79c.filesusr.com/ugd/3d514e_be8ba160925f46b8a0723b4b7bf5793b.pdf?index=true
- https://7404da97-7fcf-4d5f-9d5f-3f8644e6773a.filesusr.com/ugd/35f767_b46a0598250e4206bef794af1deb2ca0.pdf?index=true
- https://6e229dea-1f83-4be8-8cd3-388eabd4f5e3.filesusr.com/ugd/1cfe37_aeb9244a074f439e9547dd55876e849e.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e64d.bin079868c43f9874220355d2e0374f773bfd580de6ded8b2c212c682a602d3e49b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE64D | 5368 bytes |
font_01_sfnt_off0000f89e.bin81f2e5f11fafcc2330f135842d2c4d041445d81853600c251ac3dbd0a9422b5a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF89E | 11460 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.