MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, many of which are part of a link farm designed to improve search engine rankings, indicating a likely SEO spam or phishing campaign. The ClamAV detection and ML classifier strongly suggest malicious intent, specifically identified as a phishing trojan. While no scripts were explicitly extracted, the presence of embedded URIs and the overall structure point towards an attempt to redirect users to malicious websites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9953
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/award?keyword=flow+cytometry+in+hematology+pdf
- https://luzijegeze.weebly.com/uploads/1/3/4/0/134040843/guwumofiw_gidose.pdf
- https://mizavujubamu.weebly.com/uploads/1/3/0/7/130775062/tunimabupiloje_vejixe_fukular.pdf
- https://cdn.sqhk.co/tefozakozup/VqSgiih/53003967510.pdf
- https://cdn.sqhk.co/kululojilo/BgepTAJ/nifaxuxugiwirerekij.pdf
- https://cdn.sqhk.co/guzikiku/RW9MMia/22449133332.pdf
- https://rowegodidevonu.weebly.com/uploads/1/3/4/4/134468430/vorutejajipat.pdf
- https://lipixebuz.weebly.com/uploads/1/3/0/7/130740586/juwagej.pdf
- https://cdn.sqhk.co/nokowifupe/hb8ChjI/chest_x_ray_report_normal.pdf
- https://cdn.sqhk.co/bujiwamovul/hcZjcge/83198422114.pdf
- https://static.s123-cdn-static.com/uploads/4374022/normal_5ffd0ceb38ffe.pdf
- https://static.s123-cdn-static.com/uploads/4417207/normal_5fee37ed2b683.pdf
- https://ragadavifomo.weebly.com/uploads/1/3/5/3/135306528/d76ef7c.pdf
- https://static.s123-cdn-static.com/uploads/4485689/normal_5fc7d193c27c4.pdf
- https://cdn.sqhk.co/zagakobafot/N2zifX8/99139842294.pdf
- https://cdn.sqhk.co/gituridewo/Y4VLbLi/leo_and_tig_gameplay.pdf
- https://static.s123-cdn-static.com/uploads/4497353/normal_5fdc9e704584a.pdf
- https://cdn.sqhk.co/kivipemo/CBzRJjj/4831920716.pdf
- https://cdn.sqhk.co/fegukajebaj/jd1gi7Z/dungeon_fighter_online_character_customization.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://a86a6b26-b473-4b55-b9aa-7628a2bff077.filesusr.com/ugd/4f270c_fa386c23ee704b66a943ed9bcc612a55.pdf?index=true
- https://0fdd9f25-8366-4660-9463-376fd915ad39.filesusr.com/ugd/c16cf9_a3fbe279270345ebaf773807e84bba31.pdf?index=true
- https://f730d15c-1921-46d2-b6d4-288333e40990.filesusr.com/ugd/e2c223_2745501dada94cd88d0558dcee432ff1.pdf?index=true
- https://359ea524-acbf-40a7-8d58-ee96a8f10bc8.filesusr.com/ugd/ca2e76_813dd9190ff1482ab934ba9a6ab3f9fc.pdf?index=true
- https://aeedc83c-a41d-4179-9d48-e770e4c4cd47.filesusr.com/ugd/e010a7_9c44d6dfdad94af3abbd9b07386851a9.pdf?index=true
- https://bf23b77b-49a9-4bef-a898-a03cfb94aefa.filesusr.com/ugd/134172_e3da1d02e6a34927b990620da4677ffe.pdf?index=true
- https://94db4134-5784-44c5-a63d-963e509970fa.filesusr.com/ugd/9c58c5_ef13ce65b9b243bab2642c4b963d7cbe.pdf?index=true
- https://8eb0ff2f-1b5f-41fb-a82b-bf279dc7f43e.filesusr.com/ugd/868f76_399b9d73095d4e1a9cd924e74dbe25ba.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000154d0.bin4572fc8f1b3a792a88ace2cacd0982b96d8eb6c3fd70416b5bf26c0733ec5f0c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x154D0 | 5540 bytes |
font_01_sfnt_off00016798.bin73423e237402eda7676a26946d6955717f4c541fc2e8c7ec8012dcccd6bcef2b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16798 | 10764 bytes |
font_02_sfnt_off00018c7b.bin1a2b76eb92621148de57a48589384f2ed1ce1add53d2a8f9a0414c0ea737f4f8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18C7B | 16148 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.