MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are SEO-optimized and point to other PDF documents, indicating a link farm designed to manipulate search engine rankings. The document body, though heavily corrupted, contains keywords related to 'lottery' and 'prize', aligning with the 'SE_ADVANCE_FEE_SCAM_LURE' heuristic. The presence of numerous external URIs suggests an attempt to redirect the user to malicious or deceptive content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9967
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/award?keyword=effective+succession+planning+rothwell+pdf
- https://cdn.sqhk.co/soxuvezosapa/WGDigib/horse_running_speed_mph.pdf
- https://cdn.sqhk.co/nimabugokofa/aid0263/trending_hashtags_today_on_twitter_worldwide.pdf
- https://nenejiremox.weebly.com/uploads/1/3/0/9/130969141/nananuzakiwewevadi.pdf
- https://pazuvokase.weebly.com/uploads/1/3/4/6/134615635/5102623.pdf
- http://biomaniix.website/ftse_vietnam_index_factsheet5qxel.pdf
- http://alania365.ru/extending_mendelian_genetics_worksheet_answers1t3b4.pdf
- http://tanijijud.sportsontheweb.net/tibejowosojafefod.pdf
- https://jasujoru.weebly.com/uploads/1/3/1/4/131483343/f663178da4.pdf
- https://gakujoxabusu.weebly.com/uploads/1/3/5/3/135394689/8387187.pdf
- http://giwewigipebi.medianewsonline.com/60603393381.pdf
- http://noksipals.online/37454765457sm4wt.pdf
- http://ruxuzosok.mywebcommunity.org/82740307264.pdf
- https://cdn.sqhk.co/zifeduwa/biaX7bL/58223964407.pdf
- http://faceskinagainbeauty.xyz/gudozoxedofipilekanasezakw131a.pdf
- https://cdn.sqhk.co/zasemewiti/1Nsidjh/original_barber_shop_torrance.pdf
- https://nanagufema.weebly.com/uploads/1/3/1/4/131483019/001cd6e66a6f6e.pdf
- http://strapslap.online/koruxivusugeveguspz4t.pdf
- http://pirunumilusarib.sportsontheweb.net/star_trek_2009_movie_free.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/681bdcf0-1bf9-40b8-b28d-5902e28cfed1/portrait_photography_lighting_setup.pdf
- https://uploads.strikinglycdn.com/files/e015c405-37d2-47f1-ae2d-2f4ad253b059/lufaninarizuwama.pdf
- https://uploads.strikinglycdn.com/files/4f94540c-c1c9-49ad-987e-20419c4b34ad/46467484032.pdf
- https://uploads.strikinglycdn.com/files/8d6c37ad-2a87-4f1c-969d-51cf6bc3fb76/ryobi_electric_pole_chain_saw_reviews.pdf
- https://uploads.strikinglycdn.com/files/a7fc88d8-7b05-470a-9e2f-f186e74c8ee2/tagaxuxuw.pdf
- https://uploads.strikinglycdn.com/files/6b81aa47-0e9a-4fef-bb56-95758b4fb085/char_broil_grill_grate_cleaning.pdf
- https://uploads.strikinglycdn.com/files/1453aced-b054-4ebf-862b-4e17c41565f8/like_water_for_chocolate_meaning.pdf
- https://uploads.strikinglycdn.com/files/622cbb46-7088-43c2-819f-242c20c0aa1e/pejexup.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001022d.bin28c8b869e8a24ebe88c3dd1a851544b87717b59ea9682beba0fc3a425e5934fa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1022D | 5528 bytes |
font_01_sfnt_off00011514.bin6df24a6e967e6338022d01f6d6039d0ea9b7b7d41f17ea82827e040e67d236b1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11514 | 10820 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.