MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded URL that mimics a search query, likely intended to trick users into clicking it. The heuristic PDF_SEO_LINK_FARM indicates the presence of numerous external links, suggesting a link farm or phishing attempt. ClamAV detection and ML classification strongly indicate maliciousness, classifying it as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://chcial.ru/wb?keyword=how%20much%20is%20mississippi%20drivers%20license%20renewal
- https://bizumoku.weebly.com/uploads/1/3/2/6/132681494/9097440.pdf
- https://pulisojoperun.weebly.com/uploads/1/3/4/4/134487891/dupijupelalunas-magiboladiji-tavazilosojag.pdf
- https://dovenokitumenu.weebly.com/uploads/1/3/1/4/131482991/verewakamavu-kulaf.pdf
- https://static.s123-cdn-static.com/uploads/4413125/normal_5fdd5c7047810.pdf
- https://sajozigita.weebly.com/uploads/1/3/0/8/130814351/dunuvanazufu_kudukoz_ladibimamo.pdf
- https://static.s123-cdn-static.com/uploads/4417329/normal_600148facf298.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/cc023127-d927-4d87-8ecd-ea2084a4c39e/estudio_de_factibilidad_libros.pdf
- https://uploads.strikinglycdn.com/files/828d94cf-9cd4-4104-aaf0-240c9dc9ec77/dolapibigodo.pdf
- https://uploads.strikinglycdn.com/files/ae8ce3df-3a81-4fde-9e1a-55553f139dd0/sajagerafanaj.pdf
- https://uploads.strikinglycdn.com/files/9cca7df8-461f-468f-9000-d0d587f09ded/xuzufitipavupedama.pdf
- https://uploads.strikinglycdn.com/files/1d698cee-6f7a-4a37-aa37-0b54f457e073/how_to_find_curve_of_best_fit.pdf
- http://wuwazilizos.pbworks.com/f/automatic_transmission_troubleshooting.pdf
- https://uploads.strikinglycdn.com/files/3c18aff8-3370-464c-93b5-6300545e8893/90564195504.pdf
- https://uploads.strikinglycdn.com/files/7ab52934-798a-4c6c-a2e5-16a7a046a2c5/if_he_hollers_let_him_go_book.pdf
- https://uploads.strikinglycdn.com/files/75a70c97-5123-4d3b-8502-1fd7ab451b93/how_long_does_loreal_hicolor_last.pdf
- https://uploads.strikinglycdn.com/files/59724452-5965-442c-9589-d81058987190/22969480952.pdf
- http://gijorugisaw.pbworks.com/f/how_to_become_a_truck_dispatcher_in_texas.pdf
- https://uploads.strikinglycdn.com/files/9a93104e-e121-4858-8230-e84e85211b23/what_is_the_purpose_of_an_abstract_in_a_lab_report.pdf
- https://uploads.strikinglycdn.com/files/2c6e3d09-2f0d-4aa7-96cf-81391f6f4c69/liwafukorinopetobigibuwiv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e35f.bin2cc5a9194d6408b1ba4198922db04d7007fac81c6f40eb1910cb37d3de1309f3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE35F | 5424 bytes |
font_01_sfnt_off0000f5ba.bin9287865f950da562c0ed0a37e21f572822f6289863f017dc6244aecb97b24c22 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF5BA | 9588 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.