MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains multiple embedded URLs, with one specifically referencing 'hp+laserjet+2100+toner+refill', suggesting a lure for users seeking printer supplies. The heuristic 'PDF_SEO_DISPOSABLE_LINK_FARM' indicates a pattern of using disposable hosting for numerous links, further supporting a phishing or malicious redirection scheme. ClamAV and ML classifiers also flagged this PDF as malicious, specifically as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jottigo.ru/strik?utm_term=hp+laserjet+2100+toner+refill PDF link annotation
- https://cdn-cms.f-static.net/uploads/4371790/normal_5fd1c33878d5a.pdfIn PDF document text
- http://buloshnaya.site/mutokolewarzeuyx.pdfIn PDF document text
- http://zobegodu.iblogger.org/xixuponizovelabiwen.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4368751/normal_5fc942a11818c.pdfIn PDF document text
- http://reduslim-italiaoficial.site/gimuzonizikasapowapakp9k42.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4491414/normal_5fe603a33dda1.pdfIn PDF document text
- http://reawont.online/zevagujevuxokill7qqx.pdfIn PDF document text
- http://losinglotterynumbers.com/carrot_cake_nutrition_informationmlizk.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4409095/normal_6037786c6386c.pdfIn PDF document text
- http://alternativeinfluencenetwork.net/bugunun_saraylisi_37_bolum3piuc.pdfIn PDF document text
- http://artistichomesolutions.com/the_game_tv_show_season_4_episode_2542oeb.pdfIn PDF document text
- http://neroveruturom.iblogger.org/69488336047.pdfIn PDF document text
- http://durasazi.iblogger.org/another_world_achievement_guide.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4499317/normal_6041c204ac099.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4490529/normal_603c53b6a2c0f.pdfIn PDF document text
- http://sy0n.icu/isoflavonas_de_soja_menopausiazfsm3.pdfIn PDF document text
- http://wdd13.ru/20507221415edt3o.pdfIn PDF document text
- http://wugovur.iblogger.org/what_does_the_king_in_the_little_prince_symbolize.pdfIn PDF document text
- http://inostrana.com/482178893351qqoa.pdfIn PDF document text
- http://fortuneo-enligne.com/korumefojipesiejeh9.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/7a20be84-52a2-4e36-a2a4-092500928c85/what_is_included_in_the_pali_canon.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/584827cc-cc59-4e1f-92a4-0f34cb08961d/manual_chamberlain_liftmaster_professional_1_2_hp.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/07b0d58c-1552-4d17-986e-330605fa479c/still_me_jojo_moyes_book_summary.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c1b628da-7433-4bc6-bf1d-ea250367b4f8/kuzazuvozigosojufepurepax.pdfIn PDF document text
- http://nuvebuxuloruvux.epizy.com/kaspersky_antivirus_3_months_trial_free.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ddee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDDEE | 5260 bytes |
SHA-256: 5ebbda321132755acff44bdaaed5179dc2b877b20b1aa643eb5928588480f70f |
|||
font_01_sfnt_off0000efe2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEFE2 | 10908 bytes |
SHA-256: 623b6f88e6a9a59c7c0114aad21cef25faba55f3ecc4770f4ce0842222662c7a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.