MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9985
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://seumenha.ru/award?keyword=sale+of+land+act+vic+pdf PDF link annotation
- https://wolunogejafijut.weebly.com/uploads/1/3/4/6/134649672/5669841.pdfIn PDF document text
- https://xefobizedep.weebly.com/uploads/1/3/1/6/131636625/fijep_misavanakutola.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4403141/normal_601bb3b0c4147.pdfIn PDF document text
- https://texexavif.weebly.com/uploads/1/3/1/4/131454683/7857123.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4530578/normal_6003266133cf7.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4466146/normal_5ffd0d32c170d.pdfIn PDF document text
- https://ramageputa.weebly.com/uploads/1/3/1/6/131637054/dozuvo-vapapazode-kotogulo-nofelifax.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4446260/normal_60469c324b79d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4383302/normal_60253f53c94dd.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4505820/normal_604a56535a359.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4498376/normal_604580394e53a.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4417313/normal_6063da1c28cc3.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4475730/normal_5fd101a4704bd.pdfIn PDF document text
- https://wiwovadale.weebly.com/uploads/1/3/5/3/135322143/zuzibuna.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4485308/normal_5fc713c22bfe9.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://s3.amazonaws.com/rimejiguvif/high_school_lesson_plan_template_doc.pdfIn PDF document text
- https://s3.amazonaws.com/fikuvine/delta_p20_scroll_saw_review.pdfIn PDF document text
- https://156bb51f-0b62-477f-88ca-8620af00812b.filesusr.com/ugd/e3ff21_232a98ac7d9c4e3594e08e039f4cd346.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/44edb710-0064-4902-b745-6cf3f050afc6/why_is_kyocera_printer_offline.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b77421e7-2541-4f7a-853a-f945fb2c786f/best_pressure_cooker_for_canning_venison.pdfIn PDF document text
- https://6cbe2f5c-748b-4bc6-b691-25a968a47885.filesusr.com/ugd/d6b5da_d9133e94452345e893b0fe353569f25c.pdf?index=trueIn PDF document text
- https://f3ea461b-95fd-44cf-949c-5afda193840f.filesusr.com/ugd/a48928_e430393cebb74d128793e150677a94ea.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/38d91056-7dfc-454e-a6fc-93cf91914449/2012_dodge_avenger_alternator_replacement_cost.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e8ed.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE8ED | 4824 bytes |
SHA-256: 385d4ce03d0fbecaf43e630ed3aa89b6bebaa715d508ad1974900a08726e628f |
|||
font_01_sfnt_off0000f96a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF96A | 10652 bytes |
SHA-256: 73d200b736aeef865f33ac4530cc090cfeaa76a7ecf25a372055335b1a9f9183 |
|||
font_02_sfnt_off00011df5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11DF5 | 16060 bytes |
SHA-256: 5b0d2701ab39d2f69c66d7d16c60d8db0b323aa0832947137e757b5401d27330 |
|||
font_03_sfnt_off0001328d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1328D | 4324 bytes |
SHA-256: a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.