Malware Insights
The PDF file contains a large number of embedded links, many of which point to known malicious redirectors or disposable hosting. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' specifically flags a URL leading to 'dafemum.ru', indicating a phishing or scam attempt. The presence of a password archive lure suggests an attempt to bypass gateway security by encrypting a payload. Although no scripts were explicitly extracted, the nature of the link farm and the malicious redirector strongly suggest an intent to deliver a secondary malicious payload or lead the user to a phishing site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=express+referenceerror+require+is+not+defined In PDF document text
- http://gitamoravazini.22web.org/employee_job_satisfaction_questionnaire_template.pdfIn PDF document text
- http://duzakimur.iblogger.org/76519570045.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/4d48179e-96e6-4489-8fbc-12711eb0cb1f/28624261976.pdfIn PDF document text
- https://s3.amazonaws.com/zubata/frankenstein_pumpkin_template.pdfIn PDF document text
- http://gexazavere.epizy.com/87201218585.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fd01e9a4-81aa-4561-8c2e-8e7a7aa04858/32370625575.pdfIn PDF document text
- https://247e77cc-5367-4382-8586-7c5891409f42.filesusr.com/ugd/2dbf5a_a8d6266aad044dc9869eecf8a3f6d40f.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/kesumasaka/ecommerce_html_template_free.pdfIn PDF document text
- http://salilizuvozel.rf.gd/lagu_dj_asmara_terbaru_2019.pdfIn PDF document text
- http://kiziwekez.rf.gd/wozugeram.pdfIn PDF document text
- http://vegunag.rf.gd/africa_cyber_security_report_2019.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8cf5a4bc-3cff-43bb-8607-71f04c024c21/josux.pdfIn PDF document text
- https://s3.amazonaws.com/luramamelolem/darimoripejaso.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8c03025b-3b74-4bde-a1a5-3073bc7bdfa8/the_wise_mans_fear_what_went_wrong_lyrics.pdfIn PDF document text
- https://4de1274e-a26b-4e71-a0d1-d86f0cfee7ee.filesusr.com/ugd/ee4d88_aaafdef9d33b498da0b08f6193dce030.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/8677cd3c-677b-4f45-a938-04924dfd3459/76476619249.pdfIn PDF document text
- https://46b09160-81f9-4cb3-9cca-f7b5b0c0229e.filesusr.com/ugd/179cc6_7be11cdfc62b47d889444df3f6e8e688.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/figugipopar/96477532033.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a8e2ece7-91a4-4fd1-ab9d-e97ffab7672c/how_to_clear_code_on_thermo_king_apu.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ece5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xECE5 | 5060 bytes |
SHA-256: 66031ddb39d4579b270011a446598e2ed225a37bc0cc7887613737ed43cc04a5 |
|||
font_01_sfnt_off0000fe2b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE2B | 1956 bytes |
SHA-256: 1a02017d8f9dfccebdf658a6e57aaf3f1db45e167806d7a7e54ac7b5b333925c |
|||
font_02_sfnt_off0001074e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1074E | 11484 bytes |
SHA-256: 43f5ab97551ddf49627b48fd5beabb7639ff80809ea58dadbbe4d6083695a885 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.