MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which point to potentially malicious domains, as indicated by the PDF_SEO_LINK_FARM heuristic. The primary malicious URL identified is traffset.ru, which is likely used for phishing or to serve a second-stage payload. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffset.ru/123?utm_term=the+wolf+among+us+episode+1+trophy+guide PDF link annotation
- https://kagepumesafoke.weebly.com/uploads/1/3/4/8/134846889/6433676.pdfIn PDF document text
- https://xesamubi.weebly.com/uploads/1/3/4/0/134095888/a204d0f7.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4490516/normal_5fcac9f5c42e1.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4380858/normal_5f95bef04def8.pdfIn PDF document text
- https://dutaveporope.weebly.com/uploads/1/3/4/6/134600224/4662619.pdfIn PDF document text
- https://vamepuruzaf.weebly.com/uploads/1/3/4/3/134352512/zejazurivovofu_livimoji_kiful.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/98646eac-b04e-495c-918f-f010be7e1f93/92569293421.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6248a78a-6131-451f-a1af-19cb15548438/best_enchantments_for_sword.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/90c27414-1352-4820-80fa-398317023712/30927079258.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bd236aef-9d01-4106-8f22-1673346bf8e2/penuvuta.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/972e539b-3d4c-4158-89b1-3c6ffb4833c2/magistracy_of_canopus_catgirl.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0c326312-3707-48a4-a5ba-ea07ce70f20d/20391658659.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3db19b8a-9d5d-42c2-b57c-76457e86b285/death_row_records_chain_spinner.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2c8b5105-a404-41a3-912a-ed9b43f0a92a/15406454590.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7f60dc02-2001-4883-a687-bc1f0b2149af/51800527324.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d4cc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD4CC | 5648 bytes |
SHA-256: 3a7f0a5ae069b9c9d873026528272c0b7d113adf36207e5253326967856b60f9 |
|||
font_01_sfnt_off0000e7f7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE7F7 | 11252 bytes |
SHA-256: e3b0118c7635a7c6c5b41ff45ed8b7aaf952ca441081f47875f09bb69ea5d0c1 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.