MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, many of which are part of a link farm designed to mimic search results for educational content. The primary malicious URL identified is vilenefex.ru, which is likely used to redirect users to a phishing or malware distribution site. ClamAV and ML heuristics also flagged this PDF as malicious, indicating a high likelihood of malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.7621
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/award?keyword=ncert+solutions+for+class+9+english+beehive+pdf+download+free
- https://cdn.sqhk.co/fukonovum/fgggghf/sojesuvutotamuxasazisabi.pdf
- https://cdn.sqhk.co/keridola/B0hiQG5/human_puzzle_image.pdf
- https://zozabamefopofa.weebly.com/uploads/1/3/4/2/134234868/52fb546cfc746.pdf
- https://cdn.sqhk.co/womawuxinuge/j9jf0hf/94502189671.pdf
- https://lexizade.weebly.com/uploads/1/3/4/3/134368494/191258f64f7f.pdf
- https://cdn.sqhk.co/vefemenivu/hfggiaY/gravity_gun_games_online.pdf
- http://varuzajuv.22web.org/xogejewojimetaketaseguw.pdf
- http://gikilebi.iblogger.org/27816174080.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://92fed17e-af34-466b-b3fe-38cd9ef27699.filesusr.com/ugd/192d58_aadc0324ce154f69917079e283627d76.pdf?index=true
- https://s3.amazonaws.com/jazofi/xupavatulivewidedojofox.pdf
- http://pusukobu.epizy.com/sapivitulafafoturaw.pdf
- https://s3.amazonaws.com/fotepopunaj/what_does_coffee_mean.pdf
- http://vapoborino.rf.gd/all_commands_in_unix.pdf
- https://s3.amazonaws.com/ximupuv/metabolisme_protein.pdf
- https://53002a68-e35f-4167-ac88-1ab9777d7e72.filesusr.com/ugd/f5bc2a_4e636819c6b445b7968b7a489acf5baf.pdf?index=true
- http://visejatuvun.rf.gd/zapapanibemeke.pdf
- http://neduweleviwov.rf.gd/rumilikaketujogo.pdf
- https://1c896d37-30d1-4b4d-9537-98f963aae812.filesusr.com/ugd/865d50_f50b496b11ea4f20b690480625847371.pdf?index=true
- http://sujetokotew.rf.gd/61359811294.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e305.binf192eb8689acfbc48800e27cf4f2d230fc79aedd68519fc02abca221c594ab11 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE305 | 5716 bytes |
font_01_sfnt_off0000f675.bin1fb5c4a13967475e89a70088267796c24d92d2faa892c7bd0fed743c0deedd87 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF675 | 10196 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.