MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of external links, identified as a link farm, suggesting a phishing or malware distribution attempt. The ClamAV detection and ML classifier further indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded URIs point towards a malicious document designed to redirect users to potentially harmful websites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/wix?keyword=moviebox+apk+iphone
- http://ririzobe.medianewsonline.com/konuxaburobigalos.pdf
- http://gagitevanonuti.mywebcommunity.org/bersa_thunder_380_grip_screws.pdf
- https://vubosetupis.weebly.com/uploads/1/3/4/5/134594606/5807672.pdf
- http://gavediteriremuv.medianewsonline.com/bronconeumonia_nios.pdf
- https://cdn.sqhk.co/xedaberetaj/fFNFPgd/human_fall_flat_level_steam_walkthrough.pdf
- https://cdn.sqhk.co/rifojimuna/eGTV5Tc/1281531452.pdf
- http://pojapir.mygamesonline.org/rajowix.pdf
- https://datagoso.weebly.com/uploads/1/3/4/7/134718767/ranepugaf.pdf
- https://cdn.sqhk.co/toromerepowa/Dwhbwje/jurumujepapubola.pdf
- https://cdn.sqhk.co/marixefe/tijTjeM/blaze_of_battle_hack.pdf
- http://xoxapepagaxon.mypressonline.com/39963820310.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://e61e9f85-32c5-4861-9fd4-b89109084c35.filesusr.com/ugd/2e4eb4_1bba4fa438d54e32991ae4b61eafe66d.pdf?index=true
- https://9fc80a0e-b25b-4135-afeb-9811a1ea6bf8.filesusr.com/ugd/91e123_b5fa7e2dc9cc4aec8e650d2117ff1206.pdf?index=true
- https://7ec9ed57-df89-401a-953b-45744c150cee.filesusr.com/ugd/6e3131_594365987fa6400f81532d0310e1c98d.pdf?index=true
- https://ff9dba89-6132-4485-99c2-ace8a2453124.filesusr.com/ugd/c3f59f_7598912bda134da6a81192c4ea2e3337.pdf?index=true
- https://s3.amazonaws.com/sirilagewuga/lesuwoke.pdf
- https://a8a70d16-e3f0-4805-b115-4d8c62c40b57.filesusr.com/ugd/82e28d_eb37c8f802d245c3a9fcb368e1fda1f4.pdf?index=true
- https://s3.amazonaws.com/zarusegibitumet/fofivapat.pdf
- https://c1908cc8-b41e-4b5b-ab1c-53d28a7f2745.filesusr.com/ugd/913720_5ac2473e97374e9fb32f625bc11f3b46.pdf?index=true
- https://e0d0d77b-4c00-4265-bc22-f0cc5cf11ada.filesusr.com/ugd/957eb4_fea178782be94c36ba81cd0792bf64db.pdf?index=true
- https://c9b0c9dc-51ad-46ec-84b2-dbc26df53712.filesusr.com/ugd/b6f588_f093c381e3ee410eb884e3b13b659343.pdf?index=true
- https://f8d82b49-d438-4da2-b906-f876cb6fe635.filesusr.com/ugd/12dc78_d921306d9ca043968692469d0125aa59.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e5a5.bine829fdda7741ffb78ee9ac91993f4023c1ee8d1eca12576c5c2898a14c1c93a1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE5A5 | 4936 bytes |
font_01_sfnt_off0000f684.bin4f864843bf8e46673d006b33d868bf2fd83c2ffa384a01ae703aa4da9dc53af3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF684 | 11632 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.