MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are SEO-optimized and point to other PDF files, suggesting a link farm designed to attract traffic. One of the primary external URIs, 'https://resalured.ru/wix?keyword=naruto+vs+bleach+2.2+unblocked+at+school', indicates a lure related to popular media. The ClamAV detection and ML classifier strongly suggest malicious intent, likely to distribute further malware or phishing content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/wix?keyword=naruto+vs+bleach+2.2+unblocked+at+school
- https://vujugorakiti.weebly.com/uploads/1/3/4/7/134719441/luvigupuwiruneg.pdf
- http://vakexuk.22web.org/saucony_guide_iso_solereview.pdf
- https://sibanozaniso.weebly.com/uploads/1/3/4/8/134858677/jadevu.pdf
- https://lobobofu.weebly.com/uploads/1/3/4/6/134680821/1432151.pdf
- https://jugizefabugej.weebly.com/uploads/1/3/4/3/134377355/wovipo_genuzopel_fizetozipa_vopilovafasusew.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://8ac5c8e1-9174-427d-95c2-90bebb9f105a.filesusr.com/ugd/44b221_dd2eeeee2b694f51a892e6236591cc20.pdf?index=true
- http://tokumizexafu.epizy.com/cheat_engine_6._5_for_pc.pdf
- http://kidogip.epizy.com/jajapobefazunebamafaxirar.pdf
- https://0ed7c29b-d5f2-4290-8b47-add6aa38300d.filesusr.com/ugd/32a223_96c12364aaea47dbb5a48030ff6192da.pdf?index=true
- https://d1ee23ee-9ccf-45b0-80ef-1e1ff1f657c4.filesusr.com/ugd/9ef0c3_659463a8c4e34e23bbb37711093af54f.pdf?index=true
- https://8eccd3b7-fb20-4588-a5b5-4d8c58591879.filesusr.com/ugd/0e6328_4539f2e28b8448fca2b4be3b5d1b72be.pdf?index=true
- https://5366dd3f-28a3-4342-b8e5-5bed86455aec.filesusr.com/ugd/a92322_730b53ce380a4af89289dc249550941f.pdf?index=true
- http://nanabiwilave.epizy.com/technical_writing_salary_per_hour.pdf
- http://xaxuvep.epizy.com/simple_past_tense_exercises_regular_and_irregular_verbs.pdf
- http://wagivudixar.epizy.com/kewevipigajul.pdf
- http://mafovito.rf.gd/how_to_train_to_run_a_marathon_for_beginners.pdf
- https://bf6af823-cb0d-4ee8-9d5b-4f0b1de5ed24.filesusr.com/ugd/9eb187_933275c878e74d76a6bfa0a0034e411c.pdf?index=true
- http://lebemowabekoko.rf.gd/zubunape.pdf
- https://c1bbde11-5cda-4f7c-8b74-b2fe90b484f5.filesusr.com/ugd/1c8c6c_b3c77aac53fc4c1bb7b74dd3cb599688.pdf?index=true
- https://uploads.strikinglycdn.com/files/6918f530-645b-4500-9dcd-fa4bec2413c8/nikon_p510_price_in_kenya.pdf
- https://uploads.strikinglycdn.com/files/7e5b7fa5-b066-48c1-95d7-76aa8d5dba24/what_is_an_example_of_information_processing_theory.pdf
- https://3cd6846c-369c-4875-9c63-132df726a2dd.filesusr.com/ugd/7ab50f_5e56ca4d135648fa9454e206ab73da3c.pdf?index=true
- https://676a7a22-5bec-432e-92e0-9d4a0a27851c.filesusr.com/ugd/a1fb72_4ac6480a96a249008f1611c98b69cb51.pdf?index=true
- https://uploads.strikinglycdn.com/files/ecee7e35-ef63-47ca-aab3-d5e3b3dd1867/popaziv.pdf
- https://uploads.strikinglycdn.com/files/92283d45-eeb2-4a21-b151-e91af11d998d/premiere_pro_wedding_invitation_templates_free_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010693.bine6ada79466c89fbea7a27969d21cf419abefa2baab20575fe3aef06ae3428be3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10693 | 5424 bytes |
font_01_sfnt_off0001190b.bin7563a4b8c928f7b1995182dfb1f1e89c117d61df5130664c87c33b0a635f04b1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1190B | 11100 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.