MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of external links, many of which are dynamically generated and point to other PDF files, suggesting a link farm or SEO spamming operation. One of the primary URLs, 'https://nipisod.ru/award?keyword=anticoncepcional+niki+bula+pdf', is likely used to direct users to malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/award?keyword=anticoncepcional+niki+bula+pdf
- https://cdn.sqhk.co/mikitikotak/gfaehXR/tezunudugabitukuxerof.pdf
- https://cdn-cms.f-static.net/uploads/4424376/normal_604cebf924a52.pdf
- https://cdn.sqhk.co/temazajilib/iho5Bg8/kidadinojidubo.pdf
- https://cdn-cms.f-static.net/uploads/4425913/normal_5fdbdc17e882d.pdf
- https://zesidorav.weebly.com/uploads/1/3/1/4/131437831/d5a4984822d1e.pdf
- https://static.s123-cdn-static.com/uploads/4443801/normal_5fca7445d584a.pdf
- https://bumogekatagod.weebly.com/uploads/1/3/0/7/130776321/51b363ad233405.pdf
- https://static.s123-cdn-static.com/uploads/4413456/normal_600391efa202c.pdf
- https://static.s123-cdn-static.com/uploads/4369507/normal_5fffcb1eb92dc.pdf
- https://cdn-cms.f-static.net/uploads/4412164/normal_60179efb6ee1d.pdf
- https://cdn.sqhk.co/gorigaserata/U8hgW0U/asterisk_pbx_linux.pdf
- https://cdn-cms.f-static.net/uploads/4481275/normal_6031ff6af1874.pdf
- https://xizotuvulozig.weebly.com/uploads/1/3/1/8/131856772/forapezo.pdf
- https://cdn-cms.f-static.net/uploads/4382420/normal_60599d88a43c8.pdf
- https://noresewikikizi.weebly.com/uploads/1/3/1/4/131453465/gukuzotuf.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://dc383e6d-b7a3-4e67-a88a-227fa542b6c3.filesusr.com/ugd/72b0e7_f2305864b5dd430dadc10cac409d78e2.pdf?index=true
- https://s3.amazonaws.com/dewazewokib/95005734484.pdf
- https://s3.amazonaws.com/naxozelozude/doraxuka.pdf
- https://72858ab8-d36f-4bc2-b208-e5ec56e76d01.filesusr.com/ugd/3a4e0e_4fd0b583037341c7a67e217a0c004334.pdf?index=true
- https://ebbb41b5-b8b7-4bfc-9e1b-23e79ad93844.filesusr.com/ugd/5eba67_3ec9d0d8b9934896a66fa748550851fc.pdf?index=true
- https://s3.amazonaws.com/xonobijikivo/75231440457.pdf
- https://s3.amazonaws.com/vukujidor/completing_the_square_practice_problems.pdf
- https://s3.amazonaws.com/piradi/star_movies_live_tv_apps_for_android.pdf
- https://0ac950e2-707a-4e47-8bf4-daface0ea9db.filesusr.com/ugd/356f11_0e7957d3a2664c728e1eabbae200be03.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d5d0.bin5998152716579e5393c751d0df3c0c649daa82507dbf88c71fe0d946127a960f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD5D0 | 5068 bytes |
font_01_sfnt_off0000e725.bine6b25d518bfc2f8172e99118a53c439e69e199d17b0e7ffb05814b3c5720f67e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE725 | 12172 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.