MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, indicating a phishing or trojan payload. It contains numerous embedded URLs, with one pointing to 'golowaki.ru', suggesting it's part of a link farm designed to redirect users to malicious content. The document's structure and embedded links align with common phishing tactics.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://golowaki.ru/award?keyword=goldman+cecil+medicine+pdf
- https://zuvitapud.weebly.com/uploads/1/3/1/4/131406427/xunanesadibes.pdf
- https://cdn.sqhk.co/xorilulog/hapAjcG/fruit_slash_free_download.pdf
- http://lejidakoxinetog.mywebcommunity.org/kodakumetut.pdf
- https://cdn.sqhk.co/xobakidanav/ieihY4X/naxobefepu.pdf
- http://gosofejabe.iblogger.org/70177639492.pdf
- http://xojuxelase.medianewsonline.com/can_t_take_my_eyes_off_you_piano_sheet.pdf
- https://cdn.sqhk.co/pidikuso/e98id43/faily_brakes_game_download.pdf
- http://bewugexujiz.iblogger.org/affidavit_format_of_marriage_registration.pdf
- https://bexusisase.weebly.com/uploads/1/3/4/5/134596812/tivitodudomido.pdf
- http://gasurorir.sportsontheweb.net/arabic_tamil_dictionary.pdf
- http://vakiduweg.mygamesonline.org/viktor_frankl_mans_search_for_meaning.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/3734a339-9660-4518-8725-15bdccf0ad27/is_there_sugar_in_dunkin_donuts_french_vanilla_coffee.pdf
- http://peguretunemidom.rf.gd/free_training_checklist_template_word.pdf
- https://uploads.strikinglycdn.com/files/c7a13be6-cddd-4d0d-9dde-c676a94b781a/how_accurate_is_the_cva_wolf.pdf
- https://uploads.strikinglycdn.com/files/7e4f8d35-d930-486b-bc26-ef58a8439828/riser.pdf
- http://dinilemave.epizy.com/maggie_rogers_alaska_piano_sheet_music.pdf
- https://f8b57e9d-e272-4783-b6f5-6420e6b93425.filesusr.com/ugd/886b73_d532c8043bba4ac982dd225137975350.pdf?index=true
- https://538d8494-0c7d-401a-b890-0485f6bc7bca.filesusr.com/ugd/29c71c_4a644aa7fa614698b2e1535168ad4e08.pdf?index=true
- https://uploads.strikinglycdn.com/files/79f88a12-2c8b-46de-9a10-af590ba1b1e6/html_table_cellspacing_css.pdf
- https://uploads.strikinglycdn.com/files/695acd4a-edbd-42fb-b56c-610129133227/dapilekusosenosupivu.pdf
- https://1f571a09-6495-4108-bd1a-9715deae29b5.filesusr.com/ugd/b0bf26_f4d9ebe3e25046538de7031b747ace94.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000112a9.binf3ecc7898fc51c104f2f09c7fcae0a8e2cadb4544628d291e6725bdfe3aa718d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x112A9 | 5056 bytes |
font_01_sfnt_off000123d0.binb724ab04b25e673c86a6ce6a7ce066c3deb01c00bb361c39c1e77d5db52226bd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x123D0 | 11556 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.