MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The PDF contains a significant number of external links, many pointing to other PDFs, indicative of a link farm designed for SEO manipulation. The ClamAV detection and ML classifier strongly suggest malicious intent, specifically identified as a phishing trojan. The presence of external URIs and the overall structure point towards an attempt to redirect users to malicious content or download further payloads.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=shell+shockers+aimbot+script+2021 PDF link annotation
- https://static.s123-cdn-static.com/uploads/4476270/normal_60054f1bb4211.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4452846/normal_603f2b701683f.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4367312/normal_601f406bcac23.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4372737/normal_6055305e0d117.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4489241/normal_60512c5750210.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4448547/normal_605f35959cbb0.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4461211/normal_603a631644746.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4495399/normal_606b940a9d755.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4415739/normal_5fe7950ea96aa.pdfIn PDF document text
- https://jufozafofover.weebly.com/uploads/1/3/6/0/136050361/382f6d1575.pdfIn PDF document text
- https://sinaxerepedosuj.weebly.com/uploads/1/3/1/3/131398545/zisijivarosine-dapujerudik-zasedak-wugiku.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/gorajikunobixi/good_wife_season_2_episode_guide.pdfIn PDF document text
- https://s3.amazonaws.com/nakuzafol/mevupimin.pdfIn PDF document text
- https://s3.amazonaws.com/doxifuba/maregujugima.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d3b9edd9-c019-42f2-bf8a-23e245d55501/delosokor.pdfIn PDF document text
- https://s3.amazonaws.com/fotojipifuzitul/bts_love_yourself_answer_wallpaper.pdfIn PDF document text
- https://s3.amazonaws.com/divikufifir/does_priority_mail_ship_faster.pdfIn PDF document text
- https://s3.amazonaws.com/netinuwa/25894272949.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9e99e5ec-f093-487d-a5f4-9cb1fcd309a8/2011_chevy_traverse_engine_wiring_diagram.pdfIn PDF document text
- https://s3.amazonaws.com/waxapoz/a._r._c_full_form.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e97d649a-6cc8-412e-8811-9e98c7cba7af/18352934230.pdfIn PDF document text
- https://s3.amazonaws.com/sosupejuxofedo/44735252316.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e50a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE50A | 5804 bytes |
SHA-256: b9ac49b5b7c5c1362df3a2ce74d9c0a80716dd0999c69a54abb2ac2fdc860be7 |
|||
font_01_sfnt_off0000f8a6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF8A6 | 10792 bytes |
SHA-256: 66a4edda4a0f543d40891b2c182ba59f683f862e064e61cb27d53df25d22c6a1 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.