MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file contains a large number of external links, many of which are SEO-optimized and point to other PDF documents. The primary external link, 'https://pistant.ru/pbw?utm_term=who+makes+sun+joe+tillers', suggests a lure for users searching for product information. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or traffic generation through a link farm.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pistant.ru/pbw?utm_term=who+makes+sun+joe+tillers
- https://static.s123-cdn-static.com/uploads/4459796/normal_5ffdd22747cc7.pdf
- https://static.s123-cdn-static.com/uploads/4378160/normal_5fcdd1a5e6604.pdf
- https://cdn-cms.f-static.net/uploads/4411231/normal_5fd6520b1a8ef.pdf
- https://zopewurexolo.weebly.com/uploads/1/3/4/5/134519391/7071774.pdf
- https://static.s123-cdn-static.com/uploads/4411681/normal_60000cadf3904.pdf
- https://warexuzema.weebly.com/uploads/1/3/4/6/134601764/4113083.pdf
- https://daluxetito.weebly.com/uploads/1/3/5/3/135344689/1059b3c3a181fd.pdf
- https://static.s123-cdn-static.com/uploads/4474988/normal_5fe51d3e6658a.pdf
- https://static.s123-cdn-static-d.com/uploads/4465136/normal_60b64fe9346aa.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/9656fb53-5e6a-49d3-b40c-5acf730f5887/what_is_the_difference_between_a_lexus_gx_460_and_470.pdf
- https://uploads.strikinglycdn.com/files/6112c9bd-809a-41a9-bc1a-c0ec222a4e8f/75188553778.pdf
- https://uploads.strikinglycdn.com/files/1816ca7b-b12b-4fd0-b21a-12c4c01c990d/75434859125.pdf
- https://uploads.strikinglycdn.com/files/96370e0a-9003-473c-aaa2-46bfabcf22b4/donifaxu.pdf
- https://uploads.strikinglycdn.com/files/e7c49e5a-8c61-43f4-862e-673d5a1b3d66/gaxagedewolonalokopi.pdf
- https://uploads.strikinglycdn.com/files/34e3754a-f1d0-4857-b2c1-6d80ac15e237/jugokemozubuge.pdf
- https://uploads.strikinglycdn.com/files/79239661-7b5f-4623-a821-14d2ae8ada59/dovenejaganewamiwuxisopa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e094.bin8d47662f633e6ac50c5ced41ec5cc930bdbe1d793c24e12e2fe5735ba29c1a76 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE094 | 5080 bytes |
font_01_sfnt_off0000f1b9.bin2d21636b17cf14b70b9d88a4a619cfe2702f0967bf480fb3a60f96a95caab979 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1B9 | 11052 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.