MALICIOUS
214
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of embedded links, many of which point to a link farm infrastructure designed to redirect users to malicious sites. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, and 'PDF_MALICIOUS_REDIRECTOR_LINK' confirms that at least one of these links leads to known malicious infrastructure. The ClamAV detection and ML classifier further support its malicious nature, likely as a phishing or redirection tool.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/strik?utm_term=elite+ice+hockey+league+results
- https://noxepelobisuse.weebly.com/uploads/1/3/1/8/131871648/zijaf.pdf
- https://wugeneziwepuzi.weebly.com/uploads/1/3/4/4/134494794/2632278.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/3b3d28ff-b9c0-4450-8802-30bf1ee244f8/nesowidofunotepaneke.pdf
- https://uploads.strikinglycdn.com/files/a3b99204-b842-49b3-8c33-9a8e1255322b/75170386303.pdf
- https://static1.squarespace.com/static/5fc794aa849d1727bc133313/t/5fc9adbfbe6684539de74551/1607052736554/misevosajararuvepoxazini.pdf
- https://s3.amazonaws.com/nijosinizo/wamotobesojububiforifobo.pdf
- https://uploads.strikinglycdn.com/files/e03e41f3-ecdf-45df-bf6f-f0b6dd969741/500_most_common_spanish_words.pdf
- https://s3.amazonaws.com/bakoloj/asidosis_dan_alkalosis_metabolik.pdf
- https://uploads.strikinglycdn.com/files/10e57e2f-036d-4c95-ac19-18ee3fffd881/40795786408.pdf
- https://uploads.strikinglycdn.com/files/46223010-f05d-47f2-a2cf-92cba0ea0538/honeywell_rth6580wf_instructions.pdf
- https://uploads.strikinglycdn.com/files/c30312be-4516-43f5-a02a-13230757307e/68714124832.pdf
- https://uploads.strikinglycdn.com/files/67b0f451-756f-442e-898a-3263225f9c48/29025362922.pdf
- https://static1.squarespace.com/static/5fc64a44a3bf4b14abcdd78e/t/5fce05a8c836a917f932dabd/1607337385380/area_formula_of_a_circle_segment.pdf
- https://uploads.strikinglycdn.com/files/2f8a6feb-ae61-4f07-bad7-5ce3dc377a5e/gospel_wonders_noah_free_download.pdf
- https://uploads.strikinglycdn.com/files/cdce66f5-02ab-4d12-a76e-798d0cd5e384/fugizunezokezudarevuzo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000abd1.bin99c5fa8f267f5262f071e9e31396938a8ca1b4e44903f8aa89148fb7a06a9ee5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xABD1 | 5184 bytes |
font_01_sfnt_off0000bd7a.binae5511e7e0ebd2581fed4ec30254c42b35b5c08f2323a500b106f6ef4d1f5f65 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBD7A | 10916 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.