MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with a critical heuristic firing for a 'PDF_SEO_LINK_FARM'. One of the primary external URIs points to 'medvor.ru', which is likely part of a phishing or malware distribution scheme disguised as a game mod download. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://medvor.ru/pbw?utm_term=disney+magic+kingdom+mod+apk+2018+download PDF link annotation
- https://ratewanevunexem.weebly.com/uploads/1/3/2/6/132681210/e5c415.pdfIn PDF document text
- https://fipuzogafugigen.weebly.com/uploads/1/3/4/1/134108551/ef9eb175b.pdfIn PDF document text
- https://dipakexamima.weebly.com/uploads/1/3/1/0/131069759/5704b4ec4.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/8325ae8c-3cd8-4e6f-acca-b3972a4d60f2/the_mysterious_benedict_society_book_2.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9d078e59-6fbb-4836-9e36-dc53faa5b943/dantes_inferno_animated_epic_full_movie_online.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/68c95936-9728-4f2b-9777-7927701aa6ab/how_is_matter_and_energy_cycled_through_an_ecosystem.pdfIn PDF document text
- http://gibuwodebu.pbworks.com/w/file/fetch/144528099/captain_tsubasa_dream_team_mod_apk_4.3.1.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5ff5ed89-13bd-4690-b94c-2b75afd744b6/aprende_ingles_en_7_dias.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/aaf6f45c-95e7-4641-b0cf-682db8dca748/emerson_nature_essay_summary.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a159e9c3-b019-48f8-9cf8-eae4c7e8e8b0/imaginary_numbers_worksheet.pdfIn PDF document text
- http://nefusim.pbworks.com/w/file/fetch/144455163/microsoft_office_2013_activation_crack_free_download_for_windows_10.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5f5fb411-369a-4f7c-9faa-a9aa76eb2b73/zupujadusin.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/060582c8-8f41-41c4-ad1c-cedfa27469e0/nfs_most_wanted_full_game_download_for_windows_7.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fb31ae04-cae0-470e-8942-8ad4c6f49d97/85638211846.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7ab46085-3f19-4c25-80e4-afaaeca0216a/9356211135.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/46d14b4b-8368-4ffc-a4d3-3738ff41ffb9/has_four_electrons_in_energy_level_n__3.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c514f795-5b46-4fb0-8493-edf63f10c66c/89433354578.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/92730335-4355-410b-be85-89b9591dd248/epson_workforce_pro_wp-4530_ink_cartridges.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ae726357-a9ee-470f-be8b-0bf17718f380/what_is_a_channel_conflict_in_business.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f6d3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF6D3 | 6072 bytes |
SHA-256: eb4a8dba2f2243a7c3a8a0abfe2fdd5c914662b557f158882c5912edf26c06bd |
|||
font_01_sfnt_off00010b9b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10B9B | 11480 bytes |
SHA-256: 92653e98bb4f2fcaf3b2fa92ae66a1f1faa32800948ad3807b089c1a1c8a5059 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.