MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF documents. One of these links, https://jacksth.ru/wix?keyword=what+rhymes+with+guidance, is directly embedded in the document body. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or distributing further malware through the link farm.
Machine Learning
- Nyx PDF Classifier malicious score 0.9955
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/wix?keyword=what+rhymes+with+guidance
- https://cdn-cms.f-static.net/uploads/4365589/normal_601a9ba28edc0.pdf
- https://static.s123-cdn-static.com/uploads/4469135/normal_600581a757725.pdf
- https://cdn.sqhk.co/jirudumom/9icpibd/traffic_road_signs_and_meanings_in_uganda.pdf
- https://cdn.sqhk.co/soxosovave/idmCggW/runescape_old_school_wiki.pdf
- https://cdn.sqhk.co/guzufaseba/gf80jf7/5918727108.pdf
- https://namulore.weebly.com/uploads/1/3/4/0/134017746/bemezunop-boxevesul-bujasaw-namol.pdf
- https://cdn-cms.f-static.net/uploads/4384045/normal_604f8885cad20.pdf
- https://cdn.sqhk.co/xupodafib/4ib1dCm/93263469715.pdf
- https://cdn.sqhk.co/zezinojox/d6cii8W/one_gotta_go_game_food.pdf
- https://cdn.sqhk.co/sigagegijej/Qjbhi7X/perfect_closing_gift_cutting_boards.pdf
- https://bemofoserobonuw.weebly.com/uploads/1/3/0/7/130739893/9254605.pdf
- https://merejeweja.weebly.com/uploads/1/3/1/3/131381112/latexerepugoworit.pdf
- https://cdn.sqhk.co/ridasozewe/sJjdmgh/nba_2k20_myteam_draft.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://fedorahosted.org/lohit
- http://www.opentle.org
- https://s3.amazonaws.com/galinikagopit/paul_ekman_emotions_revealed_francais.pdf
- https://s3.amazonaws.com/vixuwogetiv/wedding_invite_template_wording.pdf
- https://uploads.strikinglycdn.com/files/21816992-b4c6-41f3-a7d3-61ec207fb948/gewewulurafekato.pdf
- https://s3.amazonaws.com/tarizirefevifab/catia_v5_license.pdf
- https://uploads.strikinglycdn.com/files/0e578189-5337-4815-a55d-ee32290c83e0/short_story_length_for_publication.pdf
- https://uploads.strikinglycdn.com/files/41f6ff3b-e5b0-449a-8101-3bc9f280482e/fire_and_ice_perfume_by_revlon.pdf
- https://uploads.strikinglycdn.com/files/f80d889f-81ef-4b94-a467-dacc49e9d7d0/30123161786.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
- http://scripts.sil.org/OFL
- http://www.gnu.org/licenses/gpl.html
Extracted artifacts 9
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_009_off00015605.bin36bf4bca2dbe62ed7eea770f09dcbd942e9f30cdfd175f8627c1a83adfc01dda |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x15605 | 18176 bytes |
font_00_sfnt_off0000d2cb.bine0f0922da2f1b5a441c0ab47f148b203928c2bc4519f23812ab58bc0699b7f5d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD2CB | 5684 bytes |
font_01_sfnt_off0000e6a7.bin95eb097fd2ba2029cb97fdb19699b061573cbfedc41287f141c7796daa94a342 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE6A7 | 5528 bytes |
font_02_sfnt_off0000f961.bindbaab8dcf32bfe64cb008f34eb54f5316f62236e8dffe3de49b44225404383a5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF961 | 2656 bytes |
font_03_sfnt_off00010465.binc42118b51b061dffbc196cd4866a2cf76d9f31ae9d0a8f6c06e6ad224a677b24 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10465 | 2328 bytes |
font_04_sfnt_off00010f1a.bin806d12f4c18e044784d20764d58024893796e88f204c306662924b3e907cbcac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10F1A | 2108 bytes |
font_05_sfnt_off000118e5.bin2da83060ad210a9a1743b04a22b2cc5ebb14ba7af64fbaa5f25da2d26a1b3d84 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x118E5 | 6640 bytes |
font_06_sfnt_off00012a83.bin5246067f7ff5a16e05ea4eee7417c6ef111d11e93d1b94dfc7330676a2ea41c2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12A83 | 14376 bytes |
font_08_sfnt_off000172d1.binc6f56f051084033b0538cdf61e3e457d22b7f2c2ea46d10ec59ebb2b81e63971 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x172D1 | 3276 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.