MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of external links, many of which are obfuscated or lead to potentially malicious domains, as indicated by the PDF_SEO_LINK_FARM heuristic. The primary malicious URL identified is `https://baarspo.ru/wix?keyword=san+francisco+giants+bleacher+seats`, which is likely part of a phishing or SEO spam campaign. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://baarspo.ru/wix?keyword=san+francisco+giants+bleacher+seats
- http://gifavojam.scienceontheweb.net/91637807823.pdf
- https://static.s123-cdn-static.com/uploads/4370074/normal_5ff7bae09e09a.pdf
- https://cdn-cms.f-static.net/uploads/4426075/normal_60625a91b4e00.pdf
- https://cdn-cms.f-static.net/uploads/4486053/normal_60251d3612f59.pdf
- https://cdn-cms.f-static.net/uploads/4493266/normal_6017027a987d4.pdf
- https://cdn-cms.f-static.net/uploads/4482415/normal_60634c25275c3.pdf
- https://cdn-cms.f-static.net/uploads/4472204/normal_603156a350975.pdf
- https://cdn-cms.f-static.net/uploads/4505837/normal_602240d2c1fde.pdf
- http://suxoxaxowigab.scienceontheweb.net/bagels_and_beans_menukaart.pdf
- https://static.s123-cdn-static.com/uploads/4379856/normal_600848f47030e.pdf
- http://nefozufovi.scienceontheweb.net/setobeza.pdf
- http://nefupanono.mygamesonline.org/ejercicios_de_probabilidad_y_estadistica_resueltos_para_primaria.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://e028ba52-6c86-493e-86b7-fecf7cd1c3eb.filesusr.com/ugd/bcb9fd_409327bae6824a3a9cacaa9515bfcc72.pdf?index=true
- https://uploads.strikinglycdn.com/files/7232686a-7d9a-4974-9ff2-592491905802/media_essentials_a_brief_introduction_2nd_edition.pdf
- https://91953a53-6f32-4f2a-9b2e-0f954541ff31.filesusr.com/ugd/dad90e_a06964e88c394b32858d619b2c01d718.pdf?index=true
- https://uploads.strikinglycdn.com/files/63743660-0e9e-4f03-b15a-7795df1fdb65/5346402137.pdf
- https://36c7e617-1221-4173-b726-d5bce2878801.filesusr.com/ugd/610d21_7ef388d4225e40bfad018faefea38cc6.pdf?index=true
- https://8767aa75-4bd5-48c0-94ca-24e983238001.filesusr.com/ugd/debdc1_72a114d9007e49879b255d472ce5e19d.pdf?index=true
- https://9d349da1-218b-4b59-9e37-2a90cab56d40.filesusr.com/ugd/de9003_89b683e1b69d4c12b01b719cb5686ea4.pdf?index=true
- https://ccd4a2e6-63e2-4dcb-a02e-1ae1253dabcc.filesusr.com/ugd/059ff1_77ce2fde8ec3474190ee69ea8343e90a.pdf?index=true
- https://uploads.strikinglycdn.com/files/7a22a5c4-44f1-44dd-9e65-8a44cc346bc9/red_blotchy_face_in_pregnancy.pdf
- https://uploads.strikinglycdn.com/files/5f049732-8353-4b08-a2fd-ada6e0c9796b/2008_honda_civic_service_light_reset.pdf
- https://8ee4d174-735f-4cd7-9396-c3a65dbcc337.filesusr.com/ugd/5ac313_719af7204db94e9cac6c7c273aa034ea.pdf?index=true
- https://37e79482-e567-4eff-b449-6ea9b90d4679.filesusr.com/ugd/cff0cd_4445e52e1e8048de97516db06478662a.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010521.binf9a31700a96320510d0d5c5bdf3f3d253a19ee3280f8fe30ede9f028c47b2481 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10521 | 5384 bytes |
font_01_sfnt_off00011769.binadf6203d4280ee946ed1f86b0de3ffc4c6e00eb5bde54d82601b7a0dd11f708d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11769 | 11772 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.