MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, a technique often used in SEO poisoning and phishing attacks to direct users to malicious sites. The heuristic 'PDF_SEO_LINK_FARM' specifically indicates a large number of external PDF links, suggesting an attempt to distribute or host malicious content. The ClamAV detection and ML classifier further support its malicious nature, classifying it as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/wix?keyword=mini+cooper+service+manual+download
- https://static.s123-cdn-static.com/uploads/4453579/normal_5fc67ae4b4e5c.pdf
- https://felomogolupa.weebly.com/uploads/1/3/4/3/134345494/xaxopivono.pdf
- https://rixafewokeget.weebly.com/uploads/1/3/0/7/130739987/tupadur.pdf
- https://static.s123-cdn-static.com/uploads/4388426/normal_5fdd681017f3d.pdf
- https://static.s123-cdn-static.com/uploads/4459483/normal_5fff9d90add65.pdf
- http://lokubakodo.getenjoyment.net/gudeziwujadudus.pdf
- https://kenilajapa.weebly.com/uploads/1/3/1/0/131069910/nofew.pdf
- https://static.s123-cdn-static.com/uploads/4369498/normal_6006c88f9425c.pdf
- https://vilamewu.weebly.com/uploads/1/3/0/7/130775649/7523f57d1efc3.pdf
- https://wugepazi.weebly.com/uploads/1/3/4/3/134348030/45827da20e7b1c.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/094e717e-bf40-48e2-b93e-2f13eed2528f/download_buku_marie_kondo_bahasa_indonesia.pdf
- https://uploads.strikinglycdn.com/files/464ef900-9aa7-4a9c-bd7a-ab51298269c7/fisher_price_infant_to_toddler_rocker_instructions.pdf
- http://kosezofejesuxef.atwebpages.com/what_size_sheets_fit_graco_pack_n_play.pdf
- https://uploads.strikinglycdn.com/files/7d700b6e-bbf0-4d1d-8608-dbc6fe8048ea/thomas_kilmann_conflict_examples.pdf
- https://uploads.strikinglycdn.com/files/6f6f01ab-ece5-404a-86e2-f1df343377ff/ms_drivers_license_renewal_fee.pdf
- https://uploads.strikinglycdn.com/files/8ebbf5c8-0eed-4739-87c2-935157c52bae/kuvozubur.pdf
- https://uploads.strikinglycdn.com/files/bded5ca6-5eca-4b0b-baa8-25e5923cda3f/53888145698.pdf
- https://uploads.strikinglycdn.com/files/5178f340-4d72-4f05-9b48-39e8a9e0851d/how_many_maps_are_there_in_among_us.pdf
- http://perexuwofogefo.onlinewebshop.net/do_golf_cart_chargers_have_fuses.pdf
- https://uploads.strikinglycdn.com/files/cc883c60-2d74-4d0e-87ae-12b4b5511b7d/how_to_name_a_photo_studio.pdf
- http://xejobutek.onlinewebshop.net/guwosalemukulatotivijaf.pdf
- https://uploads.strikinglycdn.com/files/92ab084b-0b5e-40b2-aae8-ae44671f1041/44983329305.pdf
- https://uploads.strikinglycdn.com/files/1d22951a-e5e2-4ddf-a235-00acc6ca91c8/braava_jet_cleaning_solution_alternative.pdf
- https://uploads.strikinglycdn.com/files/66ba6e1a-a1f9-42fe-92c7-fec58b35acf4/how_to_use_tiger_rice_cooker_timer.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f4d0.bin359ead9bea077d514cd82456053047bf6117e48f81dee572212a0284e603bb5e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF4D0 | 5376 bytes |
font_01_sfnt_off0001071c.bin18725d7704843efb27ac31c9352717631d94241d4e4c916741b7707a93940692 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1071C | 10048 bytes |
font_02_sfnt_off000129ae.bin2f4e1c662936ee067d6ac1c773a2276130ac85494ab82cb4c256f4e7d7c3b400 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x129AE | 16172 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.