MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with one heuristic specifically identifying a 'PDF link farm' designed for SEO manipulation. The embedded content, though heavily obfuscated, suggests a lure related to 'Jules jurgensen watch identification' pointing to a suspicious URL. ClamAV detection and ML classification strongly indicate malicious intent, likely phishing or a scam.
Machine Learning
- Nyx PDF Classifier malicious score 0.9988
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://garglob.ru/pbw?utm_term=jules+jurgensen+watch+identification
- https://cdn-cms.f-static.net/uploads/4421615/normal_60381830c3d31.pdf
- https://cdn-cms.f-static.net/uploads/4390643/normal_60137032a08ff.pdf
- https://xeganixirutor.weebly.com/uploads/1/3/4/5/134508666/xedisosatubotop.pdf
- https://cdn-cms.f-static.net/uploads/4468550/normal_605bfe5f94129.pdf
- https://static.s123-cdn-static.com/uploads/4411702/normal_5ffad4a031b7b.pdf
- https://cdn-cms.f-static.net/uploads/4402481/normal_603d4791bc7b6.pdf
- https://xofujudafovebe.weebly.com/uploads/1/3/1/4/131410434/wadudeniwiliboludof.pdf
- https://cdn-cms.f-static.net/uploads/4367622/normal_5fdbbf5971ecc.pdf
- https://rixidagetowema.weebly.com/uploads/1/3/4/6/134612143/36191c9.pdf
- https://sadaxolofomet.weebly.com/uploads/1/3/1/4/131453623/6648964.pdf
- https://cdn-cms.f-static.net/uploads/4446259/normal_601f940c8a6e4.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/cd82e94d-e277-4d12-b8a2-4fba0438d94d/ropirolalujo.pdf
- https://uploads.strikinglycdn.com/files/c039451a-5b50-4847-9773-a5ba0a5e50af/service_engine_soon_light_blinking_nissan_altima.pdf
- http://negovijalulu.pbworks.com/f/rijisixowojatenorejime.pdf
- https://uploads.strikinglycdn.com/files/e320d929-80da-48c0-b31d-1b722fca572c/rijiwufapimun.pdf
- http://ziduzobif.pbworks.com/f/galugefido.pdf
- https://uploads.strikinglycdn.com/files/3d70c135-5ecb-43fd-8249-55e50265824c/how_to_know_gucci_belt_size.pdf
- https://uploads.strikinglycdn.com/files/bf20e87b-6612-4aa0-b40b-94605f61efbc/54755798326.pdf
- https://uploads.strikinglycdn.com/files/7e0abe78-0644-4974-9e3d-62c3148fb9aa/new_testament_baptist_church_butler_pa.pdf
- https://uploads.strikinglycdn.com/files/00a7262f-a799-45cc-b6c7-989b54db9124/main_sources_of_carbon_dioxide_in_the_air.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f0ff.bin8e058fb27c41639c0a9ccb14a6cdf722a9801e33cb2f70ac0609a9894770d8c3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF0FF | 5324 bytes |
font_01_sfnt_off0001031a.bin7928fd7a9da909f5ca3eeaa0a414cf5d64cc56b347b1a52329d5db5555b5deb7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1031A | 11988 bytes |
font_02_sfnt_off00012b8c.bin1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12B8C | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.