MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of external links, many of which point to other PDF files, suggesting a link farm or SEO spam operation. One of the extracted URLs, 'https://lozipotod.ru/123?utm_term=hair+stylist+business+cards+templates', is flagged as suspicious and likely part of the malicious campaign. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or spam.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/123?utm_term=hair+stylist+business+cards+templates
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://4bf641bf-117a-4913-931f-55e49063997f.filesusr.com/ugd/5befcb_d3b482e1a91e493591e80dd1b354b349.pdf?index=true
- https://72b50e20-f79f-40ca-96b4-24bef83e308f.filesusr.com/ugd/1a1092_dbca620704364311998cf3c8235d5a9b.pdf?index=true
- https://s3.amazonaws.com/buponuwebi/jomafidetu.pdf
- https://s3.amazonaws.com/vesubodufisi/division_bacillariophyta.pdf
- https://68420551-d949-41c4-975b-2ae86aa6d062.filesusr.com/ugd/09c3c7_3f798bf9f68f42778c3dc9f26d6de8d4.pdf?index=true
- https://aa6d2f86-95e2-42cc-897e-6bbd71c3a116.filesusr.com/ugd/78daac_33b027a2a29b4c72a5254c2245ce785d.pdf?index=true
- https://c6f55193-7475-4343-97dd-33cb3b141b6a.filesusr.com/ugd/808d8c_394774327437446da4cb5cc561a30c0b.pdf?index=true
- https://s3.amazonaws.com/pigolo/how_long_should_morning_pages_take.pdf
- https://c6de0af5-2a4c-46da-924c-839bccb102c6.filesusr.com/ugd/5f1f0f_c181a230ac574b8790ce825c72385f68.pdf?index=true
- https://9d1e48ad-bcd7-4831-9b7b-7108443a63b6.filesusr.com/ugd/136d07_d837ec15b496445da3e37f55c5ec8f74.pdf?index=true
- https://35479656-6a94-44d6-ac55-da507c14a2ae.filesusr.com/ugd/d68318_9e63eb3b8279404a8d010852ff4b7d22.pdf?index=true
- https://dd6f0c70-611b-430f-b219-ee0593fd0e1f.filesusr.com/ugd/d60051_d8b8c5b4ee734d508ed28c838828ab26.pdf?index=true
- https://488c2ff9-9ff4-499e-8f11-525115e20b22.filesusr.com/ugd/8aba0c_8df2345509154fb8a5d6b014dd0efd5b.pdf?index=true
- https://aabf49e0-5477-4fd2-8456-a986ef8f2a87.filesusr.com/ugd/9e14ca_64185985b06343298671e653984c5eae.pdf?index=true
- https://6cf80756-66c2-4d2e-b15d-ff1677cb7115.filesusr.com/ugd/2257e8_0f68cf3c3b464d7ba0e71f9a365141a1.pdf?index=true
- https://s3.amazonaws.com/baxegezivumi/femata.pdf
- https://58eafb2e-ea74-4523-a1b2-d2e0fe9bfe54.filesusr.com/ugd/466fa0_27403d8e7905489e9d71a93d0d97401e.pdf?index=true
- https://6b137298-3864-41c5-aaa3-11744000c3c2.filesusr.com/ugd/b916f4_53b2e2a227424eb6b935edf6429a4980.pdf?index=true
- https://3465328d-eb21-4af5-a94e-b8fdacefaafa.filesusr.com/ugd/c63bf9_db9062ca914340098c4f67da65002ebf.pdf?index=true
- https://s3.amazonaws.com/vitelitubovuluj/amazon_audible_app_apk.pdf
- https://619c993e-e215-4b07-891b-88776ecab8c8.filesusr.com/ugd/1fce43_3a78dd7467254be1976561c4eeac4aea.pdf?index=true
- https://44eeb0f0-4dc9-4d8b-b3fd-cc7ace98e90e.filesusr.com/ugd/a083a1_da29e0d01af34957a7213b7eaf06060d.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000101da.bin430b0c9b187cead6d17141a74fed309758c40274bc3cd1f6a6ce97939b891196 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x101DA | 5424 bytes |
font_01_sfnt_off00011434.bina968953cc943cbba86e97677b16f7f2e6725e4e4762e6e5d7aa9facbd8c7168f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11434 | 11540 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.