MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with one heuristic specifically identifying a link farm designed to redirect users to other sites. The document body, though heavily obfuscated, suggests a lure related to Spanish language learning materials. The presence of multiple external URLs and the PDF_SEO_LINK_FARM heuristic indicate a phishing or redirection attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=regular+ar+er+ir+verbs+spanish+worksheet
- https://cdn.sqhk.co/nujidegowupi/ixUcwhf/minecraft_education_edition_download_skins.pdf
- https://cdn.sqhk.co/puvubuzu/GGQjhhg/fegomopufukixafopitesu.pdf
- https://cdn.sqhk.co/rijatazuga/jhhd0ja/1943135751.pdf
- https://cdn.sqhk.co/lomasamube/iv8jh7N/contract_killer_zombies_2_ios.pdf
- https://cdn.sqhk.co/texonatuzi/ORiighf/19040870432.pdf
- http://dazolovegom.mygamesonline.org/apft_push_up_sit_up_standards.pdf
- https://cdn.sqhk.co/fafafesabok/Bjgciha/73792858271.pdf
- https://cdn.sqhk.co/bemememu/hfLhh78/29080064247.pdf
- http://wunuvuzixuxi.getenjoyment.net/allelopathic_effect_on_seed_germination.pdf
- http://dowotezovemalo.mygamesonline.org/3318859236.pdf
- https://cdn.sqhk.co/padirazemi/Wgc08ia/simcity_buildit_cheats_no_survey.pdf
- https://cdn.sqhk.co/veletafi/thjiepi/rummikub_game_near_me.pdf
- https://cdn.sqhk.co/nodezaneripe/swjehhf/pj_masks_moonlight_heroes_gekko_game.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- http://pulitisagot.atwebpages.com/antinomie_definition.pdf
- https://2daccc73-8708-4113-a26a-4f38906335d9.filesusr.com/ugd/f65175_55a2e8450da74b4c8a4a3512c1cc2af4.pdf?index=true
- https://aa5f33e9-793b-4807-a257-9eac84d314d0.filesusr.com/ugd/aa57b2_145ff8e78e0b435eaab3d7d8dd54b758.pdf?index=true
- https://aefb6378-f3ca-470a-b9d2-22936542d087.filesusr.com/ugd/fe129c_8d72a1ea40364a76a683a38b59b67545.pdf?index=true
- http://jajogagek.atwebpages.com/dewigajir.pdf
- https://a146b927-ed54-472d-b3a8-6b137e313b92.filesusr.com/ugd/4d400c_f29ef652512a418cb473c997043b5f4f.pdf?index=true
- https://17a6c5a8-0587-4adf-8126-5b439e15a62f.filesusr.com/ugd/54bec1_65f960fdea11493db72b4df7b61f5676.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f264.bin1c0bb08547ce41533454750c6f44f3b110e21290c412f1ca4569bd0338fc8915 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF264 | 5328 bytes |
font_01_sfnt_off0001048d.bin20cc40ec6f1b894e3ef0060159e241fcbcc74a0d41f2614ee58b477f7aa04ebd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1048D | 12684 bytes |
font_02_sfnt_off00012e8e.bin7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12E8E | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.