MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/strik?utm_term=samsung+galaxy+tab+4+sm-t230nu+firmware+download PDF link annotation
- https://static.s123-cdn-static.com/uploads/4471238/normal_5ff8af3517e54.pdfIn PDF document text
- http://new-volosi.ru/32304622667fok8g.pdfIn PDF document text
- http://899themes-demo.ru/78321229617xgrj3.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4481834/normal_602a89d42a776.pdfIn PDF document text
- http://labiosdewonda.com/how_to_rig_for_flatheadtwudo.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4375885/normal_600c4a0534969.pdfIn PDF document text
- http://dreabling.online/astm_e83hhypd.pdfIn PDF document text
- http://bristol-yalta.run/boxuxijagegisaxofovasimmr2i9.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4502188/normal_600994f246b94.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://19aaccd0-9772-41b6-85c4-be118606641a.filesusr.com/ugd/a12125_6c179bfab52e43fe872ee6a22f63c9fd.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/82b834a0-4a51-428b-a620-6b6e4bf7a605/36150264023.pdfIn PDF document text
- https://61069a5e-3c5f-4884-a3c7-8c7552058b74.filesusr.com/ugd/0789d5_eef6e6896b4b4660bc7021bdc9159db9.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/6306bf69-b7e1-4f93-99b2-2f382aefea51/13301606059.pdfIn PDF document text
- https://1b3fde16-7575-45ba-b40e-8916c64185ca.filesusr.com/ugd/8874e8_2136b54ac3af41878148f8569022c6f2.pdf?index=trueIn PDF document text
- https://a9864912-ad24-422b-99f3-2d90f7703507.filesusr.com/ugd/d6af85_841c9ef5db344bb9927b3e966c9d8a65.pdf?index=trueIn PDF document text
- https://0296ecfc-28ae-4fa5-925c-67a25994cace.filesusr.com/ugd/c88839_9b500ea0c5df4cc689efc48a9923ed70.pdf?index=trueIn PDF document text
- https://fa886832-b9e3-4ce5-a98c-97da2614721f.filesusr.com/ugd/9f8050_db457da0d5a14a58888df0a77d68f75b.pdf?index=trueIn PDF document text
- https://4a1cfc67-5981-466d-a13b-75576fe7431f.filesusr.com/ugd/64e449_8ec78a51ca0c483b8cb0da2a055211cc.pdf?index=trueIn PDF document text
- https://cceb078e-1df6-42b0-9e12-359f30e42f1d.filesusr.com/ugd/e8506d_d0eeb6f99b2f4c6d9be17a3c9ef8ac87.pdf?index=trueIn PDF document text
- https://786c536d-253b-4a15-94df-129c4693a223.filesusr.com/ugd/1fc311_8a34c1059427414186261e25a3552877.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/50a5d922-00cd-43ce-908d-56a2a1ca7260/average_mechanical_engineer_salary_in_us.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5b7510a4-58ab-4f4e-81e7-a5156a1c19c8/37191807203.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4e64a16b-02e1-485c-ba75-d894b89ea475/23891689238.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/82576ae8-c8aa-4699-bc35-77041b7aff55/faxatenetugobetak.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f7e2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF7E2 | 6288 bytes |
SHA-256: 50582651952a6f4f6b516e69f3984b6fb9b101d8c8d7c156e3657d61cf7be6c0 |
|||
font_01_sfnt_off00010d55.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10D55 | 10940 bytes |
SHA-256: 942517897af5ce2d18424333dfb810f59f8b796c8b4106891adf8be3cfb4c2b9 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.