MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are SEO-themed, suggesting a link farm or phishing operation. The ClamAV detection and ML classifier strongly indicate malicious intent. The embedded URL 'https://midufefew.ru/wix?keyword=tearaway+unfolded+trophy+guide' is likely used to redirect users to a malicious site, potentially for phishing or to download further payloads.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/wix?keyword=tearaway+unfolded+trophy+guide
- https://cdn-cms.f-static.net/uploads/4383917/normal_601875ec678b4.pdf
- https://cdn.sqhk.co/motanunika/iigfvii/pocket_door_installation_instructions.pdf
- https://cdn.sqhk.co/feketukadoz/hdhhyd2/horizon_t303_treadmill_australia.pdf
- https://cdn-cms.f-static.net/uploads/4447436/normal_604a90b9a55a3.pdf
- https://cdn-cms.f-static.net/uploads/4417418/normal_603d4b463b6d5.pdf
- https://cdn.sqhk.co/kelifevaz/gcjaQgi/90424569211.pdf
- https://cdn-cms.f-static.net/uploads/4417141/normal_5fe8cecf2ea0e.pdf
- http://rasazajafatirek.mypressonline.com/84354650459.pdf
- https://cdn.sqhk.co/dolubivo/he4gjif/56659175239.pdf
- https://cdn.sqhk.co/mixenezir/gghMiek/baby_shark_trip.pdf
- http://jedusajinud.mygamesonline.org/xikitewukugoxapu.pdf
- https://cdn.sqhk.co/kojogitu/7ihgjhc/shoot_bubble_fruit_splash_descargar.pdf
- https://cdn.sqhk.co/wugeguxu/jjchcgc/the_nut_and_bolt_store_hove_bn3_5ql.pdf
- https://cdn-cms.f-static.net/uploads/4448735/normal_603c28d660144.pdf
- https://cdn.sqhk.co/fokudiwun/jbM0iij/crossing_over_meiosis_diagram.pdf
- https://static.s123-cdn-static.com/uploads/4376379/normal_5ff29d58e61aa.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://2c91b947-1dd8-401e-ae91-d595f2f75867.filesusr.com/ugd/0af078_498ae21e3b7c432abbe0fc6e829d57ec.pdf?index=true
- https://dc6b22d1-fd3c-476a-b8f1-b0505981f591.filesusr.com/ugd/ab5adf_bc02b9905dd344298c72c130197fb6d8.pdf?index=true
- https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_644cec1815cc4c00bc68e261c753a5f2.pdf?index=true
- https://b1b0174c-961c-4936-87f6-765e1132391e.filesusr.com/ugd/6cf804_ff45bac497044b089a82e13be12653ac.pdf?index=true
- http://nozozuwovore.atwebpages.com/jolly_grammar_book_4.pdf
- http://nejesezape.myartsonline.com/65253022883.pdf
- https://ef733714-782c-48ea-8991-1bc0bf0c95f2.filesusr.com/ugd/ad2ade_0b37d4ee53494525971753b35453e8db.pdf?index=true
- http://gurabagoderes.atwebpages.com/42881741840.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000125b7.bin8be9858b8d5898de2d8fae035194bc69badfa20c292776314dd55711fb632a8d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x125B7 | 5268 bytes |
font_01_sfnt_off000137ba.bin1489dc111d3d23a32373ce40a008e1336681b06bf8850baa2669c9e647669d02 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x137BA | 11068 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.