MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with a critical heuristic identifying it as a link farm designed for SEO manipulation. One of the primary external URIs, 'https://ponafet.ru/123?utm_term=pokemon+tcg+card+value+guide', is flagged as unknown reputation, suggesting a potential phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or trojan delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/123?utm_term=pokemon+tcg+card+value+guide
- http://garantiya62.ru/how_to_contact_the_wall_street_journalv7e0w.pdf
- https://pigulanofalo.weebly.com/uploads/1/3/1/4/131406379/vumez.pdf
- http://wtia.space/xosanaqv6g0.pdf
- https://fijapirugonobi.weebly.com/uploads/1/3/4/3/134315317/kapuk.pdf
- http://monoga.space/notification_sounds_app_iphoneesi31.pdf
- http://brandframeb.com/vowibolemiwonuzolaripofaklaz13.pdf
- http://poopo.ru/cystite_femme_enceintel5v9t.pdf
- https://gulijigomun.weebly.com/uploads/1/3/4/3/134350957/gogege_tomab.pdf
- https://jojumevowe.weebly.com/uploads/1/3/4/3/134314985/5751044.pdf
- http://zdsshop.top/49188150271u726d.pdf
- http://quickstore.pro/59968813441l7ygr.pdf
- http://fasadi.site/47845720160ohcr3.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/905bf4d4-40cc-4073-b7f8-f153b7e5c6b3/39982175497.pdf
- https://uploads.strikinglycdn.com/files/9f4d0287-b983-45ad-989d-6073089cc4d6/how_to_turn_on_verizon_wifi_router.pdf
- https://uploads.strikinglycdn.com/files/3e303ed6-5c84-49f3-abdd-6893e05ac404/how_to_convert_a_manual_to_automatic_transmission.pdf
- https://uploads.strikinglycdn.com/files/54fa812f-02be-41a8-aef8-4e129811e579/ham_iv_rotor.pdf
- https://s3.amazonaws.com/gavexilatuvitaz/zopuwubaku.pdf
- https://uploads.strikinglycdn.com/files/ff72f860-a828-4343-8106-3501ada7e776/35453722795.pdf
- https://uploads.strikinglycdn.com/files/d0920154-c139-4c9d-abff-937b64611f81/wakiregorogemerokode.pdf
- https://uploads.strikinglycdn.com/files/8645835e-cfce-48ad-bc4b-51824b966caa/26633939636.pdf
- https://s3.amazonaws.com/mizeteb/zitabizu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e5ef.binc211a892619262aa22d0d2bb00130f09a39bc2c594381135cd062363c46ff222 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE5EF | 5088 bytes |
font_01_sfnt_off0000f71f.bin8740861b022de179f25929a8c2adc2a5dfd787f2b5e890fbe9973cc8aa082b65 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF71F | 10652 bytes |
font_02_sfnt_off00011b98.bin05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11B98 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.