MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many pointing to Weebly and other free hosting services, suggesting a link farm or phishing campaign. The ClamAV detection and ML classifier strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a phishing or malware distribution lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9989
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/wix?keyword=navy+maritime+claims+reference+manual
- https://zizovotitimojuv.weebly.com/uploads/1/3/2/7/132712514/sivaludibex_ditadedu_tipaju_zebepo.pdf
- http://woronari.getenjoyment.net/what_is_dependency_theory.pdf
- https://degegoza.weebly.com/uploads/1/3/0/8/130873855/4503221.pdf
- https://cdn.sqhk.co/siwowoso/c2ggRQ6/bheema_tamil_movie_songs_isaimini.pdf
- http://xomutukegadoj.mypressonline.com/alphabet_coloring_worksheet.pdf
- https://rivakevalitute.weebly.com/uploads/1/3/0/8/130813818/rogosas-koxubi-bupoxunap-bezesujejusamuw.pdf
- https://cdn.sqhk.co/zaviresodew/CiiLhfF/49066021779.pdf
- https://cdn.sqhk.co/junikesiza/heWWhdf/exit_interview_form_template.pdf
- https://cdn.sqhk.co/xurajalijok/ijnPZgi/xadiduku.pdf
- http://likedizar.medianewsonline.com/maytag_quiet_series_300_no_water.pdf
- https://cdn.sqhk.co/vogoxaginoje/fGtiew8/bijimorugufe.pdf
- http://nowukusox.mypressonline.com/how_to_fix_samsung_galaxy_tab_3_battery_drain.pdf
- https://lefeputabewaro.weebly.com/uploads/1/3/2/6/132695219/jimazefuvet.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/0ac95cf0-a951-43fe-955c-18937c753d90/wivekorulupefav.pdf
- https://s3.amazonaws.com/gedesisumi/aire_totale_d_un_cylindre_formule.pdf
- https://s3.amazonaws.com/donukadizolin/made_easy_mechanical_engg_handbook.pdf
- https://uploads.strikinglycdn.com/files/d44a4519-b8d9-43d2-af84-f68a670f9629/serelununo.pdf
- https://uploads.strikinglycdn.com/files/0003703d-d2c2-4ff6-9116-2266602ad217/burger_king_fries_nutritional_value.pdf
- https://uploads.strikinglycdn.com/files/3486fcb3-3b25-44b1-a7ce-569eec62000c/godrej_refrigerator_models_with_price_list_in_india.pdf
- https://s3.amazonaws.com/gopuze/balance_sheet_format_as_per_companies_act.pdf
- https://uploads.strikinglycdn.com/files/d63456c4-538b-45b6-990e-a48e9e14b71a/how_do_i_access_an_old_google_account.pdf
- https://uploads.strikinglycdn.com/files/bd61752a-7d79-4283-a7e2-c538d080515a/resistance_bands_exercises_for_beginners_legs.pdf
- https://uploads.strikinglycdn.com/files/b365c9f1-2a20-40c1-a674-2b20b0e96199/42684971562.pdf
- https://s3.amazonaws.com/fosalizuzu/sales_commission_contract_template_uk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011324.binffb7f5d23d17fcca180c4764eca67e43abaee58853f9d5a3909ce7273b8e731f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11324 | 5156 bytes |
font_01_sfnt_off000124ae.bin4bce8a497af46ec384784a4e0140cdb6fa8dd6402a09b3c7a9e6dc386bb3f34c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x124AE | 10636 bytes |
font_02_sfnt_off00014917.bin532315dfdc59b350d447ad91845dd8cc72a836e684f536ab9a4305dc5b53fb8e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14917 | 16204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.