MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are SEO-optimized and point to documents with generic titles, suggesting a link farm or phishing operation. The primary malicious URL identified is https://kuzutuzo.ru/award?keyword=data+center+management+pdf, which is likely used to redirect users to a malicious site. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/award?keyword=data+center+management+pdf PDF link annotation
- http://zenajok.medianewsonline.com/abordaje_diagnostico_de_anemia.pdfIn PDF document text
- http://kexedeziferu.sportsontheweb.net/what_is_the_use_of_logic_gates_in_computer.pdfIn PDF document text
- http://tefuvawilutir.mypressonline.com/20439816735.pdfIn PDF document text
- http://redofokotab.sportsontheweb.net/71690096210.pdfIn PDF document text
- http://beduzevitugok.mypressonline.com/50929186260.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/d69e8d86-2c58-40c3-823e-46478ddc03c4/zopuvekufiki.pdfIn PDF document text
- https://s3.amazonaws.com/nezanurugega/pumel.pdfIn PDF document text
- https://s3.amazonaws.com/tixeligufokup/fun_games_to_play_with_friends_android.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/31b3d00f-f9bb-439f-adde-c1b2261ae15f/89055629651.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/77180e71-2aff-4925-a801-be1e82f5c4e3/romeo_and_juliet_1996_soundtrack.pdfIn PDF document text
- https://dbba0f06-1911-40f0-8c80-a2638c7f81cc.filesusr.com/ugd/b13fd1_d9c635837e9841b59cd6b622dc740734.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/1f9d2dc9-f89e-48c0-ad0d-90fed8c9afb5/the_nature_of_code_by_daniel_shiffman.pdfIn PDF document text
- http://xadebomuf.rf.gd/2867337928.pdfIn PDF document text
- http://veridipu.rf.gd/bose_soundsport_android_vs_ios.pdfIn PDF document text
- https://s3.amazonaws.com/juvuraguvutoxif/yapsal_antropoloji.pdfIn PDF document text
- https://s3.amazonaws.com/tiduro/flip_flop_tipo_d_4013_datasheet.pdfIn PDF document text
- https://s3.amazonaws.com/zolerazowubow/traducir_espanol_frances_google.pdfIn PDF document text
- https://s3.amazonaws.com/defujo/3049306441.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1856c1d5-423c-4d05-86f1-267691b7e1fa/singer_stylist_zig_zag_model_457_manual.pdfIn PDF document text
- https://s3.amazonaws.com/jemisajoda/dajutuduv.pdfIn PDF document text
- http://botogokobule.rf.gd/bezoketorine.pdfIn PDF document text
- https://ded05c8b-f0d8-42bc-a64b-daa0b63394ca.filesusr.com/ugd/99afdc_aa0ea01ba3ed465dad4a021a445c8f56.pdf?index=trueIn PDF document text
- https://5fa60de5-32ab-41ac-ba65-77330e21e623.filesusr.com/ugd/2e16aa_68b987d5e094429383d21f7010f25869.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/migivewuwe/sopesefaxetevizadojewusos.pdfIn PDF document text
- https://s3.amazonaws.com/rexogeguxosix/six_of_crows_height.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011237.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11237 | 5264 bytes |
SHA-256: 85e5cbd0d4210f7db029b5fa16ae49683ca35d1357366112620371e393c951d1 |
|||
font_01_sfnt_off00012413.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12413 | 11220 bytes |
SHA-256: afd190ac6db1537fbfafd2afe8e5ca8d6235c506b18d7bb6c470d928440d3c9a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.