Malware Insights
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The file contains a large number of external links, many hosted on disposable domains, characteristic of a link farm or SEO spam operation. One of the embedded URLs, https://pixomot.ru/pbw?utm_term=how+does+low+dose+dexamethasone+suppression+test+work+in+dogs, suggests a potential lure to disguise the malicious nature of the document. The primary attack pattern appears to be leveraging the PDF as a delivery mechanism for potentially malicious content hosted on external sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9970
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pixomot.ru/pbw?utm_term=how+does+low+dose+dexamethasone+suppression+test+work+in+dogs PDF link annotation
- https://nemaxololele.weebly.com/uploads/1/3/5/3/135304154/4376377.pdfIn PDF document text
- https://polemezal.weebly.com/uploads/1/3/1/4/131452876/e52f10b6432.pdfIn PDF document text
- https://gimelukisisira.weebly.com/uploads/1/3/4/0/134040832/6700581.pdfIn PDF document text
- https://vosaxoro.weebly.com/uploads/1/3/4/4/134469305/4951892.pdfIn PDF document text
- https://vuwurata.weebly.com/uploads/1/3/4/4/134481670/3162690.pdfIn PDF document text
- https://xikefopu.weebly.com/uploads/1/3/4/7/134748362/joxofazekezesebujo.pdfIn PDF document text
- https://towodoruzaxigol.weebly.com/uploads/1/3/6/0/136050186/biritovumipugewi.pdfIn PDF document text
- https://kupikonawu.weebly.com/uploads/1/3/4/8/134882044/35cd09.pdfIn PDF document text
- https://towavakivuno.weebly.com/uploads/1/3/5/3/135318123/tesawizema.pdfIn PDF document text
- https://rufibomorogad.weebly.com/uploads/1/3/4/5/134505720/zigijixelu_dunapafojapilan_dojatabizixew_nosukifa.pdfIn PDF document text
- https://xaranetudu.weebly.com/uploads/1/3/4/0/134016810/6239334.pdfIn PDF document text
- https://jirakevajiw.weebly.com/uploads/1/3/5/9/135966085/4416111.pdfIn PDF document text
- https://xokosawebajufad.weebly.com/uploads/1/3/0/7/130776850/niposifinozo-wanimusiwedug.pdfIn PDF document text
- https://kofutisidizeb.weebly.com/uploads/1/3/1/4/131437743/2645274.pdfIn PDF document text
- https://lidoxuma.weebly.com/uploads/1/3/4/5/134584164/lafixed.pdfIn PDF document text
- https://fuwodeku.weebly.com/uploads/1/3/6/0/136095673/1593336.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/8454e594-f217-436f-ad1d-5e87a877b4a3/how_to_harvest_and_roast_peanuts.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5cc396e5-e895-435a-b129-eb6de9bf68ea/kifugolu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d0de8e2e-cf6a-4034-8891-1e682184c174/68057518929.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/26541902-8279-4636-8977-8a09eddab252/outlet_wall_mount_for_echo_dot_2nd_generation.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0a6d0e6f-2c97-4efd-9950-ba03948f52cb/34869876328.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/19f79a31-6ae4-468e-9b47-4c11cb388027/36898476407.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2742dde3-c624-493b-abcb-6075ca43c4ca/47347980259.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e7790668-17b7-481a-902e-ec8954b39d73/24893550835.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f3ac253c-f15b-4682-b640-e29ae3f751dd/10592449406.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9008cdb2-68eb-4845-b831-e3f466ac0c5e/64774129332.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010cee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10CEE | 5560 bytes |
SHA-256: 8029811a8543ffa502e91438212ee07218a2bdeeb29c8400cdf9bb0782174b20 |
|||
font_01_sfnt_off00011fba.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11FBA | 10552 bytes |
SHA-256: 926dd7732485ad7c47d2e8db6627ce1788bb810afec4f92399cda86ec2e0e769 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.