Malware Insights
This PDF document was flagged by multiple heuristics and a machine learning classifier as malicious, with ClamAV identifying it as a phishing trojan. The document contains a mass of external links, suggesting a link farm or redirection mechanism. The 'SE_CALLBACK_LURE' heuristic indicates the document's content is designed to trick users into calling a phone number, a common tactic in tech-support scams and callback phishing operations. No scripts were extracted, but the PDF structure itself is used to host and distribute these malicious links.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/123?utm_term=assignment+front+page+format+design
- https://dilipifoson.weebly.com/uploads/1/3/1/0/131070096/pexoxewexuvigi-difemozar-faratirukawoje.pdf
- https://tixusevonatafix.weebly.com/uploads/1/3/4/6/134611731/bubemukipo.pdf
- https://wasavegod.weebly.com/uploads/1/3/4/5/134589575/tamomubijo_mibap.pdf
- https://tugofemupufere.weebly.com/uploads/1/3/4/5/134584107/nevexumori_karafokixilizat.pdf
- http://zemegulobeka.iblogger.org/libro_metodologia_dela_investigacion_sampieri_5ta_edicion_ao_de_publicacion.pdf
- http://takefeduw.iblogger.org/acknowledgement_example_for_research_report.pdf
- http://zolijava.iblogger.org/how_to_ignore_guys.pdf
- https://zuvagojajom.weebly.com/uploads/1/3/5/3/135398962/b7f00c.pdf
- http://nikibolerobika.getenjoyment.net/fisicoqumica_gilbert_w._castellan_2a_edicin.pdf
- https://molawaxurot.weebly.com/uploads/1/3/4/6/134699933/tupowedokav.pdf
- https://falatunasozenu.weebly.com/uploads/1/3/4/7/134762474/jogaf.pdf
- http://jajuviramigawo.medianewsonline.com/38328819359.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/6e310694-5923-45ee-85eb-0ecc1a9852c9/34314521798.pdf
- https://uploads.strikinglycdn.com/files/85be0f32-51ff-4581-b0a5-c7f8b1171166/how_to_use_garmin_oregon_650.pdf
- http://sipanokule.onlinewebshop.net/wikofikowalepaxagoxaded.pdf
- http://rufegojokod.epizy.com/brecon_beacons_walking_map.pdf
- https://uploads.strikinglycdn.com/files/f4a92968-a76c-4e5e-a29c-89ae23265a98/bujemiwatalokejize.pdf
- https://uploads.strikinglycdn.com/files/d871f5e5-d248-41c6-9e5b-709cad1f98e0/romeo_and_juliet_1968_full_movie.pdf
- http://luvugotanufulav.epizy.com/what_positive_feelings_does_the_poem_convey.pdf
- http://tesuzegijibonu.epizy.com/informacion_de_nutricionista_en_ingles.pdf
- https://uploads.strikinglycdn.com/files/b117c7da-665e-4f88-a853-4b0eb30228d6/xafime.pdf
- http://newikajoz.rf.gd/accounting_period_definition.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f9ce.bin10edaaadd2352a96c79d3a183eba74480f89a4ea4b00a24d3c8e1b60b35dd0ec |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF9CE | 5320 bytes |
font_01_sfnt_off00010bd1.bin5d954cb093071f6141bfb9dfea4d5f6789b699b592ca5d44982212a1eb779270 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10BD1 | 11688 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.