MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9984
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/wix?keyword=inelastic+demand+example+economics PDF link annotation
- http://pitikudefojeken.getenjoyment.net/math_symbols_list.pdfIn PDF document text
- http://mujododaziwato.scienceontheweb.net/5686583503.pdfIn PDF document text
- http://dorugatutaxovi.scienceontheweb.net/bwca_maps.pdfIn PDF document text
- http://bosemefawixuwov.mypressonline.com/depuxexizokofalilolusomon.pdfIn PDF document text
- http://vowuzemiru.medianewsonline.com/employee_contract_template.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://989eff4c-946f-4221-9817-1a8d60f2082d.filesusr.com/ugd/7edf14_3c73154581f64701ab6665b57e64269f.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/kimone/97270241670.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ad1a9d8c-6cb6-44f6-a162-566a4f70d870/13307181714.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d3d76c61-00ed-474c-ab74-48fa237ec0e4/the_dark_tower_book_1_audiobook.pdfIn PDF document text
- http://tagapibit.epizy.com/pdf_autoestima_automatica.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d9e16f09-77c0-4ef3-a4f3-52576f7ad635/giwevoxizefuwisiguvofet.pdfIn PDF document text
- https://c6506652-bf5e-4f52-be36-03dbfaede22c.filesusr.com/ugd/f74919_58b1e0f016b042c99ddb85f4adbdcac4.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/forupokisip/47714004758.pdfIn PDF document text
- https://s3.amazonaws.com/regufojalojaza/89197410344.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c49a0021-e911-4117-893b-8135755db275/20883445654.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8f838160-d23a-4e26-9e83-d00989974d62/bekewelirosujam.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3c87e8ac-e7a2-4736-8e1d-3bda59a1a345/visual_studio_2010_express_edition_free_download_offline_installation.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/165b585b-f973-4a8c-980b-70f712d6f139/lenugotozemozatoj.pdfIn PDF document text
- https://s3.amazonaws.com/voxulija/how_to_use_hoover_twin_tank_steamer.pdfIn PDF document text
- http://goxabepod.rf.gd/36181976604.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fc7f23c3-8650-400f-a8f8-ecee56db00e9/53126894395.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7cb7dc20-36a5-46d5-ae09-3bebe3b1c968/how_to_use_a_ti_baii_plus_calculator.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00016b31.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16B31 | 4916 bytes |
SHA-256: 54bbcfa266e3d8f512039b3113ea9693f9693cca1bb1a483aeecd64295596753 |
|||
font_01_sfnt_off00017bc5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x17BC5 | 12908 bytes |
SHA-256: e320db51ada4f57f67c09c73c457c22bece3762b44c3826922ee2d827f524012 |
|||
font_02_sfnt_off0001a81d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A81D | 16252 bytes |
SHA-256: 61fd50a710c1f138e2ff2bab56c55329594f41bdc650d1bbec5a3e9d858803b7 |
|||
font_03_sfnt_off0001bda9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1BDA9 | 4324 bytes |
SHA-256: 1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.