MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with one heuristic specifically identifying it as a 'PDF_SEO_LINK_FARM'. The primary malicious URL, 'https://chcial.ru/pbw?utm_term=how+do+you+know+when+the+hoverboard+is+fully+charged', is likely used for phishing or to redirect to malicious content. ClamAV detection and ML classification further support its malicious nature, indicating it's a phishing or trojan variant.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://chcial.ru/pbw?utm_term=how+do+you+know+when+the+hoverboard+is+fully+charged
- https://cdn-cms.f-static.net/uploads/4368741/normal_603e045c14caf.pdf
- https://cdn-cms.f-static.net/uploads/4490365/normal_5fd85f0777b1d.pdf
- https://gutalekosipotix.weebly.com/uploads/1/3/4/3/134351461/sezevekemizubul.pdf
- https://cdn-cms.f-static.net/uploads/4408990/normal_6049f20edccbc.pdf
- https://dubasatipin.weebly.com/uploads/1/3/4/4/134459773/repavoxojobewijoxani.pdf
- https://zatenumidepav.weebly.com/uploads/1/3/0/7/130776458/ridakimopuzilibi.pdf
- https://lojavexir.weebly.com/uploads/1/3/5/9/135963097/gavevegemonimofebi.pdf
- https://jotitotibewava.weebly.com/uploads/1/3/1/3/131383271/9010438.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/f59fe5d3-0abd-4210-882c-3054932ddbfb/feeling_words_that_start_with_o.pdf
- https://uploads.strikinglycdn.com/files/1465a799-d4dd-49b5-9f1a-d7f2dc472c96/kotaragewagofekiriledo.pdf
- https://uploads.strikinglycdn.com/files/2f847a5c-b088-4b9d-a8af-42075cdb9e9f/what_psi_should_lawn_mower_tires_be.pdf
- https://uploads.strikinglycdn.com/files/b5746888-3221-49ea-9458-d691c48267c3/54144275534.pdf
- https://uploads.strikinglycdn.com/files/ad59f65a-529d-4d48-88cc-8e4c0701a324/what_is_the_motto_of_boy_scouts.pdf
- https://uploads.strikinglycdn.com/files/e8f53fe2-9b61-4bbb-aee0-c35af7c88f63/roxuriraboret.pdf
- http://pojaweku.pbworks.com/w/file/fetch/144451623/wafixukisiberuragatuduni.pdf
- https://uploads.strikinglycdn.com/files/a11073a7-b340-49ac-a748-96fde5a40415/magekaweg.pdf
- http://puzavofan.pbworks.com/f/how_to_count_fetal_movements_at_39_weeks.pdf
- https://uploads.strikinglycdn.com/files/29458ede-98df-45b4-bd87-8db287467779/tus_zonas_erroneas_resumen_en_11_puntos.pdf
- https://uploads.strikinglycdn.com/files/8188c6f3-6a42-4f11-b4f8-b9ff036079c5/realidades_2_capitulo_1a_answers_page_15.pdf
- http://wijozuzapusa.pbworks.com/w/file/fetch/144439200/libifejaxig.pdf
- https://uploads.strikinglycdn.com/files/efd34643-aaca-4d0a-a6ca-c1be71c47089/best_roulette_strategy_2020_reddit.pdf
- https://uploads.strikinglycdn.com/files/8f6c6738-fc03-4f1c-831a-c77310c3c192/how_to_change_skin_in_minecraft_cracked_1.15.2.pdf
- https://uploads.strikinglycdn.com/files/6fe0b63b-68df-4ca5-8a11-13763bdb7ee3/bexuwopuxipepepediwefiv.pdf
- http://naxenuve.pbworks.com/w/file/fetch/144447942/47025888138.pdf
- https://uploads.strikinglycdn.com/files/1352ea14-9205-4b67-b9dc-ed0344e9ba87/what_is_a_bad_ace_score.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e7f7.bin15abd5c3087072d2d9300a6be70b8ef48b49ffe3db443bf194b1ec6392f52699 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE7F7 | 5704 bytes |
font_01_sfnt_off0000fb75.bine576f997b9123135d3c88d6fee7ec7216aa67decfd257a9b9651bad47d3e1d0d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFB75 | 11052 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.