MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan distribution attempt. The document contains a large number of external links, many of which are likely part of a link farm designed to obscure the primary malicious URL, https://xezojetit.ru/strik. The presence of a password-protected archive lure suggests an attempt to bypass security gateways by encrypting the actual payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/strik?utm_term=how+to+update+2017+ram+uconnect
- https://vejazejama.weebly.com/uploads/1/3/1/3/131381369/3423976.pdf
- https://vosifiteke.weebly.com/uploads/1/3/6/0/136049758/8569678350f.pdf
- https://fejixugemab.weebly.com/uploads/1/3/4/6/134681032/felozexadijigeguwu.pdf
- http://italy-small.space/escape_room_level_38_answer_appauu7z.pdf
- https://fetevemukimagon.weebly.com/uploads/1/3/4/8/134896640/5795494.pdf
- https://redobalopubijav.weebly.com/uploads/1/3/1/3/131380120/e753d4cc83c.pdf
- http://allwoman.site/free_lodger_agreement_template_word60q2o.pdf
- http://national-verifyteam.com/suzasnsk6z.pdf
- https://xofajusas.weebly.com/uploads/1/3/1/0/131069744/a77b7.pdf
- http://flash-sar.online/grocery_shopping_template_free_printablettafs.pdf
- http://autobaff.xyz/647426359419wz8u.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://b9ecad59-ee1c-469f-8402-ddbad3bf215f.filesusr.com/ugd/84dab8_d6209c95f2f7419db5d05326597fb161.pdf?index=true
- https://6c8ebe11-725c-420b-823a-68bc39d02ad2.filesusr.com/ugd/3e87bf_d24bd41056bb4962a89780a592a5f77b.pdf?index=true
- https://d6477b75-8e4d-4453-8bbc-a86a6009e57c.filesusr.com/ugd/261d41_45aa8003dfc04d96b83e0fb7434bc9ce.pdf?index=true
- https://uploads.strikinglycdn.com/files/f1b993fa-3c0d-41e8-b664-803b0f241be7/3077049531.pdf
- http://fasevebozumip.rf.gd/49291170225.pdf
- https://uploads.strikinglycdn.com/files/7a9026d1-1aed-4997-8e21-9c3d279ea6c7/nosewidok.pdf
- http://jovawat.epizy.com/ibm_spss_modeler_premium_installation_guide.pdf
- https://31c8a3d4-0132-49f1-a04f-09c79d03e01f.filesusr.com/ugd/a4da84_0f2485cbb1dc45e8a2983306569da33b.pdf?index=true
- https://cd489911-dc6d-4439-b408-84622343fb93.filesusr.com/ugd/d8e941_9506e3f73b4b44b1b26860e55e222762.pdf?index=true
- https://uploads.strikinglycdn.com/files/e45c0546-117b-4751-961b-b07ecf4b8a50/juwusotulovedezajuguf.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fcdc.bin621ae2e3c2e030403f0fa702c61866f5953754bc8da54843285aaf5c0de4ca00 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFCDC | 5468 bytes |
font_01_sfnt_off00010f7c.binc48e2191cee8fe50247dc0a6f74c25aa9bce924fce792b92d5e6ed2402c53e21 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10F7C | 11332 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.