MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The PDF file contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various domains. One of the primary external URIs, 'https://zajinet.ru/strik?utm_term=dyson+v11+animal+cordless+vacuum+cleaner+%2526+bonus+accessories', suggests a lure related to product searches. The ClamAV detection and ML classifier strongly indicate maliciousness, likely related to phishing or malware delivery through these links.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=dyson+v11+animal+cordless+vacuum+cleaner+%2526+bonus+accessories
- http://gagimubu.mywebcommunity.org/alexa_commands_in_spanish.pdf
- http://bevamifugidujew.scienceontheweb.net/azan_ke_baad_ki_dua.pdf
- http://logunej.iblogger.org/information_asymmetry_in_agriculture.pdf
- http://lelekelosutov.getenjoyment.net/kovofiwikozegogokozuwa.pdf
- http://rigojakivuvemi.iblogger.org/47627676499.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/0bfb3587-9ec5-4d18-a756-9cdadd1d853a/what_milestones_should_a_3_month_old_have.pdf
- https://s3.amazonaws.com/kisagoz/2296073830.pdf
- https://c02a3fa2-970f-4384-b4fa-7a60184a1b73.filesusr.com/ugd/1da3fe_45cf87882b17433eab26b4608c467d0d.pdf?index=true
- https://uploads.strikinglycdn.com/files/a6cfdb35-35cd-4966-8909-c619baaef3ba/vajulexamufolina.pdf
- https://s3.amazonaws.com/poguvelefa/fifty_shades_freed_full_movie_download_dual_audio_480p.pdf
- https://uploads.strikinglycdn.com/files/ea18166d-a632-433c-93cb-3c5adcfd2d39/47759181553.pdf
- https://uploads.strikinglycdn.com/files/8ab53fd4-b2c8-45da-9df4-d3380f75006f/how_do_i_pair_my_afterglow_headset.pdf
- https://165abacb-5525-4e66-971c-c167d859e756.filesusr.com/ugd/f3f2a5_dda3c157cc10499e9883023884c33556.pdf?index=true
- http://tebuwawezizafes.onlinewebshop.net/they_say_i_say_free_online_book.pdf
- https://uploads.strikinglycdn.com/files/dca6dae7-8ab1-4973-92e1-6b62d0c944e3/where_to_watch_the_draft_lottery.pdf
- https://s3.amazonaws.com/xumakomowi/movixeb.pdf
- https://uploads.strikinglycdn.com/files/4bed13ff-0a9c-4fcb-a433-07a32eb945b0/hp_probook_4530s_bluetooth_drivers_for_windows_7_64_bit.pdf
- http://sugudilun.epizy.com/reality_capture_crack_free.pdf
- https://0502d5d0-a0f5-47b8-bc1c-644c46e4e431.filesusr.com/ugd/6cabbb_76621f7c411b437f92a4fd22c44ca601.pdf?index=true
- https://uploads.strikinglycdn.com/files/52842283-5ef8-499e-be73-5501bf47f7e9/denow.pdf
- https://uploads.strikinglycdn.com/files/910e24f2-45be-4bf5-a62b-536b0c06f003/modetoreroji.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f7ff.bin7878ffbc12260d46154e367e30e59b0a541a74516b6eeaffdea37ec724fcbcdc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF7FF | 5300 bytes |
font_01_sfnt_off00010a06.binfd6b281cec1b4136631b94ee8e083f9e96f377320598e1ee278ead73e793a82c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10A06 | 11076 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.