MALICIOUS
184
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.8840
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://catamma.ru/pbw?utm_term=how+to+run+python+program+using+terminal PDF link annotation
- https://nubodizigo.weebly.com/uploads/1/3/5/3/135346475/9f785b1514e613.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4379626/normal_6018f44b75a57.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4409239/normal_5fddb988ac08c.pdfIn PDF document text
- https://kukezedom.weebly.com/uploads/1/3/4/6/134629177/c044f2029c9.pdfIn PDF document text
- https://biwimukapol.weebly.com/uploads/1/3/1/3/131398517/06f0f0da.pdfIn PDF document text
- http://biwonuv.pbworks.com/f/lingo_license_key_15.0.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b388572d-6fe8-4e6e-9919-45fe0d2a8ec1/61570039568.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/74212596-6186-466b-8245-9ab2bf252a33/realidades_2_ch_3b_vocab.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b3eefdc0-4be5-429d-a1e3-3d06c283804f/manual_del_casio_g-shock_5081.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c5a0521d-9e73-4b75-a50e-c1a43b406b1b/52288405092.pdfIn PDF document text
- http://vikiruji.pbworks.com/f/tubibowitu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b6801a26-628c-438c-b718-68257642482a/nijenumirarer.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/49f0c170-2420-4cb9-92eb-6d81efd1f074/how_to_summon_william_afton.pdfIn PDF document text
- http://bovojigu.pbworks.com/w/file/fetch/144712812/gretel_character_traits_the_boy_in_the_striped_pajamas.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1276d95b-9b88-42ee-87ec-30b1bfecd44b/girl_from_ipanema_tablature_guitare.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cd251715-9e7a-47c8-9681-d24202b8743e/22326490828.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d5aab4c3-b382-4062-9fda-6939b59e5250/ergobaby_omni_360_how_to_use_forward_facing.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/79bf681b-2ba2-4c00-93bd-2a289be98911/interstellar_hindi_dubbed_full_movie_filmyzilla.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cb347e18-a0f9-43bb-9c1c-797ca3e5790b/how_to_reset_rca_tablet_with_reset_button.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4f7515b4-497d-4b59-ab7f-83bd79049082/planeacion_estrategica_tactica_y_operativa_conclusion.pdfIn PDF document text
- http://dajodovilav.pbworks.com/w/file/fetch/144534288/64481731581.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d6d0d0c6-f483-4ab6-9d80-e8eb5440c8ff/temupojunokagasozedinomej.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/843f6ebf-390b-4e49-b9cf-41f83aa73c95/king_edwards_lichfield_ofsted_report.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.