MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are to PDF files, indicating a link farm for SEO manipulation. One of the primary URLs, 'https://soxebez.ru/123?utm_term=android+studio+proxy+shadowsocks', suggests a potential lure related to software or proxy services. The ClamAV detection and ML classifier strongly indicate malicious intent, likely for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/123?utm_term=android+studio+proxy+shadowsocks
- https://vonepegoparopew.weebly.com/uploads/1/3/4/3/134352316/kuxel.pdf
- https://navitadewota.weebly.com/uploads/1/3/4/0/134017874/99304f572.pdf
- https://fefokepixax.weebly.com/uploads/1/3/1/4/131452923/9032715.pdf
- http://grenkasalo4.xyz/725131013775h3hp.pdf
- https://static.s123-cdn-static.com/uploads/4374517/normal_5fcb71ceb7343.pdf
- http://flowerport.store/bosigamimugaloromde89b.pdf
- http://meetcabinets.xyz/85563217558igbgw.pdf
- http://usacreditmonitoring.info/653494131247nsgp.pdf
- https://static.s123-cdn-static.com/uploads/4481552/normal_5fca58e8d076f.pdf
- https://sodefabufu.weebly.com/uploads/1/3/4/4/134473286/bumewemotekagaf_zoxijijokipedag_xiwigelaka_vavoranujuvejog.pdf
- https://cdn-cms.f-static.net/uploads/4444882/normal_6038905080252.pdf
- https://revogofoti.weebly.com/uploads/1/3/3/9/133999152/0c20e10b3d.pdf
- https://cdn-cms.f-static.net/uploads/4457011/normal_5fe9af997f319.pdf
- http://trend-sales.fun/tajoxafazawujh884d.pdf
- http://garderob-podolsk.ru/how_to_determine_polarity_of_a_power_supplysv32f.pdf
- http://fenellalucynelle.info/cisco_networking_essentialsu727n.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://e4586023-485a-43f1-9451-2d404684c5b7.filesusr.com/ugd/95ff22_fa6c9380751b4665a2113d0bfe7205a0.pdf?index=true
- https://7ef5d8b8-74ac-4e0a-b0a0-fa61ca6462a8.filesusr.com/ugd/23e9be_4dfafe3ec71043349c7ba46020ddf9fe.pdf?index=true
- https://13ea8442-998f-4f14-ba3b-7f37e53a414c.filesusr.com/ugd/008a9f_429e04a49b584e668553c1f9ac1444c3.pdf?index=true
- http://tokekiloxak.epizy.com/beginnings_and_beyond.pdf
- https://1639490a-f715-481e-9fb1-af38d332269b.filesusr.com/ugd/a59130_c7190ff7801d446680ad3a33e64021b4.pdf?index=true
- https://f3b86e06-b3aa-4ee1-82f7-79049f3379a8.filesusr.com/ugd/0c4fd2_3769784823c5444eb2e2dee34e47fb13.pdf?index=true
- http://zonatenitisa.rf.gd/dhakad_chhora_full_hd_movie_free.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fc95.bin710862cfc49368ec8d3644b976d8fea524a16ead528fe3f4d8973019e893d975 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC95 | 49920 bytes |
font_01_sfnt_off00019437.bindcbb75b3cb06ad52b0e89cd9e01acc9240a57b24f1d600994122b0799e32a78b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19437 | 5444 bytes |
font_02_sfnt_off0001a6cf.bin640d00d6d45d5d42ad1017f53bec17d6bde996d2bda8160c79c5c585560b3e62 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A6CF | 16864 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.