MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jottigo.ru/award?keyword=orphic+argonautica+pdf PDF link annotation
- http://winwites.space/what_are_the_major_arcana_cards_in_a_tarot_deck0uwtb.pdfIn PDF document text
- http://closemaze.com/mozart_bassoon_concertosvmt2.pdfIn PDF document text
- http://drovazvenigorod.ru/zovukisoi3wr9.pdfIn PDF document text
- http://lawobulobatidu.22web.org/sea_fishing_tackle_for_sale_ebay_uk.pdfIn PDF document text
- http://mejikisevupepen.iblogger.org/bahrain_visa_application_form_for_pakistani.pdfIn PDF document text
- http://rutenowataba.iblogger.org/laletoxi.pdfIn PDF document text
- http://znakomstva18x.site/xizarozamopufadusotujoki9ji6p.pdfIn PDF document text
- http://gifofebitatine.iblogger.org/fumewowa.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/nowonovege/meditation_guided_imagery.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9c0b4325-8a23-4150-bf89-d5af0be7bffe/is_there_a_free_gps_app_for_iphone.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4fcd73e3-2863-42b8-bbc2-5e50e01d0013/donofobokuvinita.pdfIn PDF document text
- http://gawusozuf.epizy.com/linizimidif.pdfIn PDF document text
- http://titegerekarirov.rf.gd/ankusam_video_songs_free.pdfIn PDF document text
- https://s3.amazonaws.com/devuxuzejozam/ruvasasexux.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c3fd5081-9fd3-4acb-8317-616a99cd2178/principal_business_activity_code_florida.pdfIn PDF document text
- http://pixagese.rf.gd/53165506092.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ee6753c2-2441-4445-bfa9-b060288a40a6/14471039512.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/18eac219-dc8f-4a52-899e-5abe5fca2704/74829174631.pdfIn PDF document text
- http://gebilame.epizy.com/34962164890.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/185a7670-7bba-4e2f-8e00-df1f8d2c8da4/94435392391.pdfIn PDF document text
- http://digegaleviverab.rf.gd/perry_anderson_el_estado_absolutista_resumen.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cd4e7980-1951-4747-bcea-b64e2070bcbd/cen_tech_battery_charger_desul.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a18656a6-e71d-4406-b03e-3300f9910f6f/fisher_price_toy_box_bench.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000172f7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x172F7 | 5236 bytes |
SHA-256: da797129f036df6043e81969aff546985a81948a464a453e7926882dfbd50a6f |
|||
font_01_sfnt_off000184c1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x184C1 | 11396 bytes |
SHA-256: 8638beabe6b37d655a60fb4677c35bf70479623ce2ad97e0d7fc97a3213d6142 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.