MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/123?utm_term=profit+and+loss+statement+balance+sheet+example PDF link annotation
- https://cdn-cms.f-static.net/uploads/4371003/normal_604b84e3f0677.pdfIn PDF document text
- https://jimixinig.weebly.com/uploads/1/3/1/1/131164312/manuzaru.pdfIn PDF document text
- http://tonedomopoja.scienceontheweb.net/69468437817.pdfIn PDF document text
- https://tunawirivam.weebly.com/uploads/1/3/1/4/131437064/0032b4ec661ebd.pdfIn PDF document text
- http://pedaxofanor.mywebcommunity.org/how_to_fold_up_nordic_track_ski_machine.pdfIn PDF document text
- http://dipunag.getenjoyment.net/landslide_ukulele_chords.pdfIn PDF document text
- https://bafizotadax.weebly.com/uploads/1/3/4/7/134761596/pozojub.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4392651/normal_60161a2e266f1.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4451753/normal_602a17fa01680.pdfIn PDF document text
- http://rijewomel.scienceontheweb.net/60002607544.pdfIn PDF document text
- https://niforobufuxir.weebly.com/uploads/1/3/4/5/134512868/xutaxerigi-lakeworoda-fazujokabape-vevozeganulalas.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4365636/normal_600c9a456457d.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4453890/normal_5ff6d1b8b072a.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/e1da7951-5ee5-4ca5-81ea-8ad019d1a84a/the_tin_forest.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/29d6b08e-c1c2-4738-8a69-75ab457ad8fd/banakapa.pdfIn PDF document text
- http://nifusotajezunur.atwebpages.com/que_es_el_manifiesto_comunista_resumen.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1466b113-dd1f-46b4-96d9-45f87c4e6d70/have_yourself_a_merry_little_christmas_chord_chart.pdfIn PDF document text
- http://widifusi.myartsonline.com/ews_10_reservation_form.pdfIn PDF document text
- http://nixomirorubu.myartsonline.com/what_is_the_opposite_word_of_loneliness.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b31b25a9-7529-4bb9-b32e-c767a80e1a54/how_to_reset_fleck_5600sxt.pdfIn PDF document text
- https://s3.amazonaws.com/zedilegol/waguvomepeto.pdfIn PDF document text
- https://s3.amazonaws.com/kumasala/21821572186.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f02e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF02E | 5604 bytes |
SHA-256: 38234e3aa17a416cb21ff56f0382aa04ad8d5dab5fa60fb1a8d3eed6ac09a88d |
|||
font_01_sfnt_off00010315.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10315 | 11392 bytes |
SHA-256: ac6abdd3997332beb2af81fa4a7e1b8c5c9af16ff35f41a0fb570b0f37a14010 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.