MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, many of which are part of a link farm designed to manipulate search engine results. The presence of a ClamAV detection for 'Pdf.Phishing.Trojan' and an ML classifier score of 0.916901 strongly indicate malicious intent. The document body, though heavily obfuscated, suggests a lure related to 'stock market basics' to drive users to these malicious URLs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9169
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILEDThe cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/award?keyword=stock+market+basics+pdf+in+telugu PDF link annotation
- http://francobusiness.com/fronius_5kw_inverter_spec_sheetsi06c.pdfIn PDF document text
- https://xaweregosakub.weebly.com/uploads/1/3/1/4/131407668/wuvaxidazewera.pdfIn PDF document text
- https://mirajaxudedina.weebly.com/uploads/1/3/0/7/130775596/3634176.pdfIn PDF document text
- https://pufenenuboz.weebly.com/uploads/1/3/0/7/130738511/98fcf8c9ad1.pdfIn PDF document text
- http://nuverlites.online/baweriwesifurixixa9eewn.pdfIn PDF document text
- https://xutifapob.weebly.com/uploads/1/3/2/7/132712150/waxofiguwiwuvup.pdfIn PDF document text
- https://garanokuwepo.weebly.com/uploads/1/3/0/8/130874617/wumofurolu_zemezufoxe_rusojiligise_wezuvuv.pdfIn PDF document text
- http://srakan.space/52128661039wjwdk.pdfIn PDF document text
- http://55571.ru/gradus_ad_parnassum_debussy_imslpxblbe.pdfIn PDF document text
- http://bilet-pdd.site/autocad_electrical_drawing_template91bwd.pdfIn PDF document text
- https://nenodomamik.weebly.com/uploads/1/3/4/0/134095987/6d4c2270dcb5b5.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://s3.amazonaws.com/temujonuwu/b_t_c_book_ka_full_form.pdfIn PDF document text
- https://s3.amazonaws.com/visagogijulep/case_files_pediatrics.pdfIn PDF document text
- https://s3.amazonaws.com/kopisigapub/12050610229.pdfIn PDF document text
- https://s3.amazonaws.com/dejazuvorira/54501588463.pdfIn PDF document text
- https://s3.amazonaws.com/mejifavo/40611232735.pdfIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f6f1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF6F1 | 5664 bytes |
SHA-256: 92be463f2eaf66b34a6d383169f16ddf3eb21b0f2926c93a8fcd6a77c35f2319 |
|||
font_01_sfnt_off00010a05.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10A05 | 10428 bytes |
SHA-256: 0e8179c89d89d8853e4ca17dafd426b4e5957d100aa98d93eabff997b22384ee |
|||
font_02_sfnt_off00012db4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12DB4 | 4324 bytes |
SHA-256: d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.