MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains embedded links, with a primary malicious URL identified as 'https://resalured.ru/strik?utm_term=how+to+set+up+total+gym+platinum'. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting a link farm for SEO manipulation or malware distribution. ClamAV detection and ML classification strongly indicate malicious intent, likely phishing or a trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/strik?utm_term=how+to+set+up+total+gym+platinum PDF link annotation
- https://mokenexub.weebly.com/uploads/1/3/4/4/134478104/8374223.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4470231/normal_60439b8952590.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4503791/normal_6004b63adc3d8.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4474220/normal_5fd1c2b0644bb.pdfIn PDF document text
- https://vogaxuruxav.weebly.com/uploads/1/3/4/3/134352923/8673500.pdfIn PDF document text
- https://kibanelamuvudu.weebly.com/uploads/1/3/0/9/130969844/mofasagidewimakiwozu.pdfIn PDF document text
- https://gemujofu.weebly.com/uploads/1/3/4/3/134372819/95334.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4372707/normal_606197f49c987.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/3224bed4-e289-4321-80b0-40d983d2001e/wuvasenujedosat.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/347c77f6-4862-4f64-995c-53c9a28b2548/panasonic_telephone_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5c121078-b614-48c8-9fd9-396d059976ee/sistema_politico_mexicano_libro.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3aa74352-9b23-419d-8993-bf0804b6953b/17546146538.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b6c60663-93b4-43ae-8305-1d547d4bafaf/mr._coffeer_cafe_barista_bvmc-ecmp1000_espresso_maker.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6c75919c-35e2-41aa-88b8-a567627cd7ff/44534333047.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4b1eea79-a855-4b50-91ae-b95c5c988ddb/guitar_licks_in_g_major.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b8569234-7784-4efc-973f-f7fef7e031d3/how_to_fix_my_shark_navigator_vacuum.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4b072f8d-7ffd-4465-b067-8952be200f4b/how_to_reset_an_iphone_4_that_is_disabled_without_a_computer.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3cf486ea-7c65-4769-8633-c9a47fac1471/88317487716.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/489f1a20-d0a1-478a-864f-bdf6116a62e4/26446082016.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/69384488-385a-4245-8f83-d339a3be8d47/how_many_watts_to_charge_milwaukee_18v_charger_use.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/660a3c75-5738-403c-8304-889294e51258/41591154495.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/803f3da1-e63c-4a7e-a0e1-758e63c5f1c9/zibajejope.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/80ede863-fe72-4b9d-88dc-a1ee4d9271c1/which_is_better_gentle_leader_or_halti.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010cbe.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10CBE | 5200 bytes |
SHA-256: 4b2b4866300db65ca8ef532d98311c61de5739896a408280c221db0ca878a876 |
|||
font_01_sfnt_off00011e7a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11E7A | 11360 bytes |
SHA-256: 24a45b94104b7c81889fabc2d86e77f53d3409ba4b9ede8e0f225167ea8432d8 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.