MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The document contains numerous external URIs, many hosted on disposable domains, suggesting a link farm or phishing lure. The presence of 'utm_term' in one of the URLs indicates a potential tracking mechanism for phishing campaigns. Although no scripts were explicitly extracted, the PDF structure and heuristic firings strongly suggest it's designed to redirect users to malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9945
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/strik?utm_term=asus+p9x79+deluxe+memory+compatibility
- http://riniwovefaraw.22web.org/sheet_metal_gauge_to_millimeters.pdf
- http://tesopinafap.22web.org/guided_reading_for_ell_students.pdf
- http://rabisuxegebe.iblogger.org/pugumom.pdf
- https://jodawebodo.weebly.com/uploads/1/3/4/6/134634345/8486487.pdf
- https://lofokuvowuvi.weebly.com/uploads/1/3/4/3/134362742/namarurodimile.pdf
- http://kudikadip.getenjoyment.net/excel_2013_download_mac.pdf
- http://losamaresufalu.22web.org/wimujalug.pdf
- https://zofazozudu.weebly.com/uploads/1/3/0/7/130739697/d764f33447662.pdf
- http://wirajamosilun.22web.org/bcbs_il_medicaid_prior_auth_form.pdf
- http://sotinifox.22web.org/morphology_of_brachiopods.pdf
- http://medilawibume.scienceontheweb.net/aminoacidos_ramificados.pdf
- https://dekitinuro.weebly.com/uploads/1/3/4/8/134871397/rafunugojamejegev.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://dodavofonov.rf.gd/13308838817.pdf
- https://7835c217-6b95-46a1-915a-76cdebae3fe0.filesusr.com/ugd/debfb4_bcba97ac7dc54e319749384dbc6415aa.pdf?index=true
- http://fataragoreb.myartsonline.com/93216101961.pdf
- http://fuxewon.epizy.com/28725228923.pdf
- https://s3.amazonaws.com/dexodekelaseki/satuloripidaxopagevox.pdf
- http://nojititama.epizy.com/naomi_junichiro_tanizaki_read_online.pdf
- http://gijafusatuvaxoj.rf.gd/35991433296.pdf
- https://s3.amazonaws.com/retisovojor/merger_and_acquisition_examples.pdf
- https://s3.amazonaws.com/sefabe/english_dictionary_word_meaning.pdf
- https://bf5f3f24-cfb9-4aec-9f01-83e6d863dc5b.filesusr.com/ugd/1f4526_7456e6104fc5420e9bf57e6eeeabdcc2.pdf?index=true
- https://8b5ac0f3-2bc4-49a6-9a99-2541af31b215.filesusr.com/ugd/f2ef67_5853f63be3914772a547497c3767e2d6.pdf?index=true
- http://padegijogul.atwebpages.com/beware_of_pity_stefan_zweig.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://savannah.gnu.org/projects/freefont/
- http://www.gnu.org/licenses/
- http://www.gnu.org/copyleft/gpl.html
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 6
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00012ef0.bin776742c3e46157a190edad277a6b48c58a43dde6e94fc2239f4344e13287efdf |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12EF0 | 6608 bytes |
font_01_sfnt_off00013f2d.bin1ff7b2cfd7d450d998118f2935b53414bbee804aec8bbedfd53659855b515c5f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13F2D | 3272 bytes |
font_02_sfnt_off00014ad4.bine309832782f2748eee00534c5929f31986671bfb006f281c182c2c5559557627 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14AD4 | 5752 bytes |
font_03_sfnt_off00015e5c.binc7a0857ce7b1ccf58e5bed0a6ae5dc0556aa1cdff0258fb6080825fe92601256 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15E5C | 16548 bytes |
font_04_sfnt_off0001938c.bin7e1b8edc3b1474c059a5a7223b6edc0d1d40ce96319c9b8bfb9a4152bb1b120e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1938C | 17128 bytes |
font_05_sfnt_off0001ac91.binb5bcee897f5cd82a953a79815ed68fa9b5c28620dab33c9aaf3562c30bcc3329 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1AC91 | 6084 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.