MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with a critical heuristic identifying it as a 'PDF_SEO_LINK_FARM'. The document body, though partially corrupted, suggests a lure related to 'algebra 1 worksheets pdf with answers' to drive traffic to these external sites. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or ad fraud.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/award?keyword=algebra+1+worksheets+pdf+with+answers
- https://cdn.sqhk.co/tiwefuxab/r7hcOgh/neon_sign_air_conditioner_repair.pdf
- http://mopewogubit.getenjoyment.net/nasutilapatadizosobasisen.pdf
- https://zasevolonuto.weebly.com/uploads/1/3/5/3/135335071/2717226.pdf
- http://nadefememidep.medianewsonline.com/cute_newborn_baby_girl_winter_clothes.pdf
- https://cdn.sqhk.co/bemaxopig/dICR4he/sort_stacked_bar_chart_excel.pdf
- https://cdn.sqhk.co/saligoliti/aNggjhk/vesowosipepe.pdf
- http://xuvaxujogilo.mygamesonline.org/banuvopegoxowerudabudaba.pdf
- https://cdn.sqhk.co/vozevadijut/jj0igwy/gestion_d_equipe_au_travail.pdf
- https://vasoxalevevox.weebly.com/uploads/1/3/4/4/134477515/435e51a8.pdf
- https://cdn.sqhk.co/remimidotomi/ij3xhiU/windy._app_precise_local_wind_weather_forecast.pdf
- https://nerukime.weebly.com/uploads/1/3/1/3/131379394/7433893.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://jeximojela.myartsonline.com/babotefededoworom.pdf
- https://s3.amazonaws.com/jumedemimo/free_of_wonderful_images_of_nature.pdf
- https://s3.amazonaws.com/gajakelegeza/21061798808.pdf
- http://pexirud.onlinewebshop.net/bernardo_kliksberg.pdf
- https://s3.amazonaws.com/wumodukubaru/19657289547.pdf
- https://s3.amazonaws.com/fibesezati/why_use_bayesian_statistics.pdf
- https://s3.amazonaws.com/samopakamefap/16364834009.pdf
- https://s3.amazonaws.com/voxipanovigepiv/jibedikepusufa.pdf
- https://uploads.strikinglycdn.com/files/d9fc15b9-923c-4420-90ef-fe60b58db283/lakshmi_ashtottara_lyrics_in_tamil.pdf
- https://s3.amazonaws.com/vukusa/what_is_an_anthropocentric_view_of_environmental_ethics.pdf
- https://s3.amazonaws.com/sefiwegegagu/clocks_and_calendars_aptitude_problems.pdf
- https://uploads.strikinglycdn.com/files/a426b32e-4957-4756-9638-41a7149a832d/peros.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ed0d.bin3cbf419d86f30e994596b74e343e6a1243bc2df6ff3c7c74d9e7731802ee76ff |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED0D | 5640 bytes |
font_01_sfnt_off0001004f.bind21b314b792c079599020cac64727f465c252ac4b8c53c999ff28b5f1daa572e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1004F | 10604 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.