MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ClamAV as 'Pdf.Phishing.Trojan' and a machine learning classifier indicated a high probability of maliciousness. It contains a significant number of external links, with one pointing to 'jumiwimov.ru', suggesting a link farm or redirection tactic. Although no scripts were explicitly extracted, the PDF structure and the presence of numerous external URIs indicate a phishing or malicious redirection attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/strik?utm_term=tissot+t+touch+2+titanium+review
- https://cdn.sqhk.co/juzogimuju/h0Pkidz/neha_kakkar_song_wedding_da_season_hai.pdf
- http://copyrightmediahelp.com/wokenoxabiwedpdy8j.pdf
- https://cdn.sqhk.co/kivemonezub/GZSyvia/nokiteviziwode.pdf
- https://cdn.sqhk.co/tizudukokeni/Unqb6hg/verizon_mobile_find_my_phone.pdf
- http://tihefers.online/404845658407h6j8.pdf
- http://goodxday.xyz/types_of_qualitative_research_design_and_its_definitionfjcc5.pdf
- http://feldhaus-klinker-plitka.ru/baby_cot_sheets_adairs203lv.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://4bf641bf-117a-4913-931f-55e49063997f.filesusr.com/ugd/5befcb_8b7b22a739b54d88ae2361b1f9e4ef14.pdf?index=true
- https://s3.amazonaws.com/setaxilitozuko/scrum_master_cv_template.pdf
- https://uploads.strikinglycdn.com/files/086a00dd-9477-4ad7-98e3-ed7d48bfc7f0/59881766007.pdf
- https://s3.amazonaws.com/sulasatevirexo/31202821959.pdf
- https://d6b7b3c7-8429-4d82-9d75-5d5d09e763cc.filesusr.com/ugd/a8c229_ba3157defe87460f8f52339f2d9fe4a8.pdf?index=true
- https://5a98ae10-8c7e-48da-b83f-9bcbc644cfa3.filesusr.com/ugd/9a8764_8e758a90a0ce45388f37e3f80b254aa1.pdf?index=true
- https://f74ea38a-ab8d-49a0-8d31-9a1d7ce64423.filesusr.com/ugd/5ceade_f2d22b6da4ee4ddb81988dac573fb8c9.pdf?index=true
- https://0c17d2ad-06a2-4efd-9128-26148cac6670.filesusr.com/ugd/44320b_8532b0f151c04749b0a1ccaa742f0402.pdf?index=true
- https://uploads.strikinglycdn.com/files/912895bc-3a6d-40c4-9306-9fec6ceb0550/cyberpower_pc_front_fan_not_working.pdf
- https://uploads.strikinglycdn.com/files/7fe0b767-88d8-41c5-afbb-fc82ae17f026/twilight_breaking_dawn_part_2_full_movie_watch_online_123movies.pdf
- https://s3.amazonaws.com/tolivajupeku/89384523195.pdf
- https://3f46bf15-0a8c-4e80-b3e5-a2e3bf90e008.filesusr.com/ugd/8e6e76_1bd4d056e5224605ae1c9ed808a2600e.pdf?index=true
- https://46a1ac71-481d-4a85-b709-d40f3a189542.filesusr.com/ugd/143c98_e9ed8cdbc83d4b048509fc54d29d9a5c.pdf?index=true
- https://uploads.strikinglycdn.com/files/e8c492fd-0518-43c9-ba77-4717182ef3ae/how_to_program_xfinity_x1_remote_to_samsung_tv.pdf
- https://535a9070-e28a-464b-adc5-c02ad08be00b.filesusr.com/ugd/9df9d6_a426c2dd1a0f4bf88dfc4ee8f7b124e1.pdf?index=true
- https://s3.amazonaws.com/jakujakula/xogunoboxufudavoge.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fa6a.bin61212cfed14804eda8780ab76fe52b41d6e4a6e3167b4cb33ea3dd43eff69dd8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA6A | 5240 bytes |
font_01_sfnt_off00010c24.bineef45fe009dbcd4377e10b1a60051f288a20fcea6f7da63253abaeae6cd7b16a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10C24 | 10932 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.