MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ClamAV as Pdf.Phishing.Trojan and a machine learning classifier indicated a high probability of maliciousness. The document contains a large number of embedded external links, many of which point to suspicious domains, suggesting a link farm or phishing attempt. While no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of malicious intent, likely related to spearphishing.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/wix?keyword=why+won%2527t+you+answer+me+lyrics
- http://scm03.ru/20704862065aufh1.pdf
- http://cheatyou.site/starting_strength_3rd_editioni48qu.pdf
- http://jeruxawi.iblogger.org/anonytun_pro_apk_2017.pdf
- http://3bureaureport.info/dna_structure_worksheet_answers54w2c.pdf
- https://static.s123-cdn-static.com/uploads/4393762/normal_5fe50c80670e7.pdf
- https://malugeko.weebly.com/uploads/1/3/1/6/131636988/6715459.pdf
- https://jixejuterekafiw.weebly.com/uploads/1/3/4/5/134508928/00456cec.pdf
- http://pijitirade.iblogger.org/can_android_iphone_apps.pdf
- https://static.s123-cdn-static.com/uploads/4372384/normal_5fe36b6243815.pdf
- http://help-business-media.com/hindustan_unilever_products_price_list_inj9gbx.pdf
- https://cdn-cms.f-static.net/uploads/4475988/normal_60103dcf2e7b3.pdf
- https://bomaripuxizidul.weebly.com/uploads/1/3/4/9/134901287/jaxexolog-fajirof.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/murudute/propiedades_del_acido_acetico.pdf
- http://sodividupoz.epizy.com/how_to_use_suunto_d4i_dive_computer.pdf
- https://s3.amazonaws.com/bejikefowu/avensis_2015_manual.pdf
- https://s3.amazonaws.com/rimejiguvif/house_rent_agreement_format_in_english.pdf
- https://s3.amazonaws.com/begijufadi/paxutinujozaviwasaze.pdf
- https://s3.amazonaws.com/wudibirewuduto/24540259362.pdf
- https://s3.amazonaws.com/marimejerebo/android_studio_emulator_cannot_connect_to_internet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eebd.binccb235320460ac779f53520b6008757d77b49dd8460f8c904a1af3f85f465837 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEEBD | 5280 bytes |
font_01_sfnt_off000100ab.bin93b952f53d08e814de9c29ad75b080e62e603b3b87eb06f2bdb80f255d9b8e71 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x100AB | 10408 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.