MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged by multiple heuristics as malicious, including ClamAV detection for 'Pdf.Phishing.Trojan'. The PDF contains a large number of external links, suggesting it is part of an SEO spam or link farm operation. The primary URL, 'https://oniceh.ru/wb?keyword=o%20que%20fazer%20quando%20as%20fezes%20n%C3%A3o%20saem', is likely used to direct users to malicious content or phishing pages.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://oniceh.ru/wb?keyword=o%20que%20fazer%20quando%20as%20fezes%20n%C3%A3o%20saem
- https://static.s123-cdn-static-d.com/uploads/4374682/normal_60b54754435e4.pdf
- https://zisetilu.weebly.com/uploads/1/3/1/3/131382786/vemaxavokibal.pdf
- https://murudogukezopo.weebly.com/uploads/1/3/4/3/134320821/siledasi.pdf
- https://static.s123-cdn-static.com/uploads/4489850/normal_5ffccd5e5209c.pdf
- https://static.s123-cdn-static.com/uploads/4477629/normal_5fe4f1857dd46.pdf
- https://cdn-cms.f-static.net/uploads/4387061/normal_6066fb3feec0a.pdf
- https://cdn-cms.f-static.net/uploads/4474223/normal_603b71aa6ead2.pdf
- https://pakimisubimoge.weebly.com/uploads/1/3/0/7/130776027/dasejotitadivopi.pdf
- https://cdn-cms.f-static.net/uploads/4365600/normal_603be61755ac8.pdf
- https://static.s123-cdn-static.com/uploads/4417406/normal_5fe18296d02dc.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/1abf4198-b48b-4e96-a305-5488c0bf5101/vurajapupadasiwiruwaxij.pdf
- https://uploads.strikinglycdn.com/files/1a960bfc-35da-44f5-9810-3c8bd9a7abe5/6250719737.pdf
- https://uploads.strikinglycdn.com/files/4de30d6e-8e51-4e53-a9fb-a1633f21a9c8/tighten_manual_eject_screw_ps4_slim.pdf
- https://uploads.strikinglycdn.com/files/1d09e451-79e6-4683-b000-cd2d72a69b7f/rebekoniz.pdf
- https://uploads.strikinglycdn.com/files/c75429e8-14eb-49a5-ae06-6b6c54ef2e65/nitotiduzerezewexu.pdf
- https://uploads.strikinglycdn.com/files/a008b1c9-be57-4498-9c21-35342e150918/the_sum_of_the_interior_angles_of_a_polygon_is_1440._how_many_sides_does_the_polygon_have.pdf
- https://uploads.strikinglycdn.com/files/8bbaede2-f4e0-4e69-8f20-c2046a30f0f6/guerra_de_guerrillas_significado_diccionario.pdf
- https://uploads.strikinglycdn.com/files/521fac79-c9a8-4459-8abd-4a4fd5e282d1/what_movies_are_coming_to_netflix_australia.pdf
- https://uploads.strikinglycdn.com/files/354cd30d-fdf2-42be-9bb0-dd6cf3f18690/senuvev.pdf
- https://uploads.strikinglycdn.com/files/5142a8ba-c1a3-4521-ae4c-d6e47b752428/chapter_26_section_1_origins_of_the_cold_war_worksheet_answers.pdf
- https://uploads.strikinglycdn.com/files/30877439-08eb-41b6-92da-edcbe430ce94/mikefuxulupibodazupapit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eec7.bin5f653d70acf651418bfcbd30fd902ed9fc1c6b7f9ab858824089c95a9e9afe42 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEEC7 | 5296 bytes |
font_01_sfnt_off0001001c.bin9c9d4b36eaf12896abbd7a3bb6f4f5758e11844f203dde4d6286c67e59ab40e8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1001C | 13272 bytes |
font_02_sfnt_off0001290b.bin8405bb6ca9a6fb718a2e910e1cdde4d74ac2122cab0061dc5f772322db9c7ccd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1290B | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.