MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many pointing to disposable domains, suggesting a link farm or phishing operation. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to redirect users to potentially harmful websites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/wix?keyword=the+dao+of+capital+pdf PDF link annotation
- http://kakolamilasaru.medianewsonline.com/tokyo_ghoul_anime_order_reddit.pdfIn PDF document text
- http://fawikenaxalu.scienceontheweb.net/46110417752.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/52595202-08c5-46e6-aa61-80b729d49cca/java_interview_questions_for_freshers_with_answers.pdfIn PDF document text
- http://xonekumoti.rf.gd/28167345141.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/117d633a-c306-43a0-b231-dfcaaa231ea8/19659374035.pdfIn PDF document text
- https://d5cf7a15-73c9-49c9-ad57-d4f0303abb0c.filesusr.com/ugd/0d002d_822c67b6646446d1b06d2209597cca64.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/759bc4d2-d1c6-42ca-9712-1bb626a89dda/35871944531.pdfIn PDF document text
- https://c504e2ef-f928-4e80-b5b1-fc05046f432e.filesusr.com/ugd/247f25_8d775d6df1874f15997b243d93adb08e.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/505a37d6-3f5c-4b79-913c-720ded69600c/descargar_msica_de_ala_jaza_y_ana_gabriel_huelo_a_soledad.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c781c40f-6216-45be-a32d-b87ca31b7b7a/catch_me_if_u_can_full_movie_watch_online_free.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6942b432-b8e5-467c-b27d-1f50fdb56076/thetford_rv_toilet_bowl_cleaner.pdfIn PDF document text
- http://kitilogokufalu.atwebpages.com/44942481881.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/43107811-d56b-4e88-a545-04eeacb96b5a/the_bloody_chamber_feminist_analysis.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/afcde23a-cc7d-4584-bf09-dd8ad1402709/what_age_are_the_magic_school_bus_books_for.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/60018ea9-62ff-4a74-aef5-2fb1980cf9b3/omega_juicer_frozen_dessert_recipes.pdfIn PDF document text
- https://fea67d75-dd3b-4bdd-af05-748e92ec8a52.filesusr.com/ugd/05900a_eb9bdbde0b86475591b5d4d0aabdcab2.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/1a31cfac-d7e2-411a-8735-695cfd295332/gluten_free_food_ideas_for_party.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7ade3186-778e-46e2-a311-5019b123ae33/50717214844.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4dcec101-b4e9-4dd5-ba78-a61f7c6b905a/shadowrun_dwarf_weight_chart.pdfIn PDF document text
- http://penobugixova.atwebpages.com/vertical_continuous_casting_process.pdfIn PDF document text
- https://60659a61-a27b-47ea-8eac-a81775c62269.filesusr.com/ugd/7a7fb1_96a911dc3ea24792a42674a362813ff0.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/55f7c2a2-b25d-4f43-b7a2-db083105c61a/all_my_sons_movie_plot.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4466a1ae-54a5-4f57-a8a3-4bb395d55ab6/listado_de_verbos_irregulares_en_ingles_con_traduccion_al_espaol.pdfIn PDF document text
- http://vetanafajodomek.epizy.com/papoxatedu.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001002b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1002B | 4916 bytes |
SHA-256: a39350bbb8c18bd18428568246fe19e98e3a73decf4b7b9b60bc4778fe01f358 |
|||
font_01_sfnt_off000110e9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x110E9 | 11000 bytes |
SHA-256: ed86366bde71bc79d70ab21bf2c9dd4120a4687828edcbff8c15acecab8e87ce |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.