MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are to benign-looking PDF files, suggesting a link farm or SEO manipulation tactic. One URL, https://seumenha.ru/wix?keyword=concept+of+language+of+research, is flagged as unknown and is likely the primary malicious destination. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://seumenha.ru/wix?keyword=concept+of+language+of+research
- http://uaregroup.com/does_bruno_get_gassed_in_the_boy_in_the_striped_pajamasewysu.pdf
- https://cdn.sqhk.co/jogujufuza/id0ltja/magusufotur.pdf
- https://cdn.sqhk.co/woteruzid/cgdhhj6/ganidobovifaguvedudire.pdf
- http://shoop-fe.ru/bible_baptist_church_near_meweu7m.pdf
- http://rbqjkwklnd.xyz/korean_journal_of_management_accounting_research91gk6.pdf
- https://cdn.sqhk.co/zasemewiti/RhdhfRH/attack_on_titan_live_action_eren_titan_form.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://6c8027e1-9878-41b3-a9ef-32ba2b6bcd02.filesusr.com/ugd/185811_7c2698f723ba49398efcdbf34b542aec.pdf?index=true
- https://s3.amazonaws.com/bojafazes/74740250189.pdf
- https://s3.amazonaws.com/debiwelof/9981700608.pdf
- https://s3.amazonaws.com/bitizopovopaso/aditya_369_songs_free_320kbps.pdf
- https://s3.amazonaws.com/rekorewexidiwo/natadurobefadufu.pdf
- https://s3.amazonaws.com/fukezavazuj/what_is_knowledge_base.pdf
- https://4c5ad993-366d-4b3a-aa99-9b6f56583180.filesusr.com/ugd/01e791_2a149bcd33bf48e8ae07897bcb60f116.pdf?index=true
- https://944bcc21-9f45-42c2-9889-8cf837fa5d1c.filesusr.com/ugd/50f869_461e1bb1d38f42f88651ce6694928b7b.pdf?index=true
- https://uploads.strikinglycdn.com/files/221f13ab-8c8b-4dbd-ac0a-7b3992b420b1/cisco_stealthwatch_flow_collector_4200_datasheet.pdf
- https://s3.amazonaws.com/firigugixujotov/how_to_tone_up_your_abs.pdf
- https://uploads.strikinglycdn.com/files/1d6a59a8-f371-4144-b6f5-69031b184806/my_husbands_secret_wife_lifetime_movie_cast.pdf
- https://uploads.strikinglycdn.com/files/70f236eb-4c8e-4d07-b3f0-1dfde39cf979/46408977393.pdf
- https://uploads.strikinglycdn.com/files/605b871f-beea-49a3-ac6c-58e93e9f3314/joseph_prince_church_texas.pdf
- https://uploads.strikinglycdn.com/files/0c09bf37-fd4b-4a64-9136-11fe7bbceb69/79836324036.pdf
- https://s3.amazonaws.com/domegagowevag/simple_tajweed_rules.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00013cf1.bin4b9450d0e6b4658cea4022f2d179f5cac16ad59a1765b73ca2e81e2ca2e8cbeb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13CF1 | 5184 bytes |
font_01_sfnt_off00014e8e.binc750df88daee04484166b2244d711f46830a083fb392fe9e10deff7da598e957 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14E8E | 11828 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.