MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. One of these links, https://jumiwimov.ru/strik?utm_term=school+psychologist+job+london+ontario, is flagged as unknown reputation, suggesting a potential phishing or malicious redirect. The ClamAV detection and ML classifier further support its malicious nature, likely related to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/strik?utm_term=school+psychologist+job+london+ontario PDF link annotation
- http://gazozaxuk.getenjoyment.net/guia_ada_diabetes_espaol.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/vufuzewasi/kshatriya_movie_song_hd.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e7f596da-fa46-4e2e-997c-dee4e78d1e5a/honda_es6500_generator_not_charging_battery.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/557d6374-8be6-432e-bcd9-aa3596ebdb2d/how_to_create_a_website_with_wordpress.org.pdfIn PDF document text
- https://s3.amazonaws.com/mubefula/delete_my_gmail_account_android.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/316a7bb5-3e2e-4a2b-b3b4-d2d276c0b79b/sole_elliptical_e95.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6592e280-11fe-46da-b4d1-3a4940974a44/24286792911.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/63a45ccc-c6a9-46df-bdce-cf603ba71adb/que_come_el_oso_negro.pdfIn PDF document text
- http://wuwedilejom.myartsonline.com/joladalanomowejufabiluvom.pdfIn PDF document text
- https://6680615c-3592-42a6-94f3-b98e474b5330.filesusr.com/ugd/252546_8e568a7f5366451ea22a3d8d8b8b2855.pdf?index=trueIn PDF document text
- http://tuminexozuvino.atwebpages.com/20516544725.pdfIn PDF document text
- https://s3.amazonaws.com/rezugekolaba/rizizewesatuxuboxowa.pdfIn PDF document text
- https://s3.amazonaws.com/napejaxosinages/standard_cv_format_for_job.pdfIn PDF document text
- https://s3.amazonaws.com/lazolu/cartoon_movie_website.pdfIn PDF document text
- https://s3.amazonaws.com/nosepevozux/pajajuzumazukedevut.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7dd0bd90-5d6f-47bc-892d-7c0fbc96ef49/what_is_a_driving_permit_in_texas.pdfIn PDF document text
- https://s3.amazonaws.com/bopuxosavubare/45440195171.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1139d427-0f33-4c30-873e-254dac4545f7/heinemann_a_level_french_grammar_practice.pdfIn PDF document text
- https://e9593579-f51f-4dc6-af55-2543ab512b45.filesusr.com/ugd/37952c_be1d6dd18fc94221b2a8f5dec86fcb70.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e9f4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE9F4 | 5756 bytes |
SHA-256: a5f25a3a73a4770c4a55b2e357fd0bdb2e212f86ff9b8f927f26ba0393517a05 |
|||
font_01_sfnt_off0000fd88.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFD88 | 11032 bytes |
SHA-256: 6f24f85d4eb53c04a68b183b93c6b67cd5e15015b1d4a15fdae5d8033fdf22f3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.