MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are to PDF files, suggesting a link farm or SEO manipulation tactic. One prominent URL, 'https://jacksth.ru/strik?utm_term=roman+empire+flag+spqr', is directly embedded and appears to be a malicious domain. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/strik?utm_term=roman+empire+flag+spqr
- https://cdn-cms.f-static.net/uploads/4447877/normal_60526710011a3.pdf
- https://cdn-cms.f-static.net/uploads/4428331/normal_601ba74f2c6a3.pdf
- https://static.s123-cdn-static.com/uploads/4406775/normal_5feb0e53c99de.pdf
- https://cdn-cms.f-static.net/uploads/4470211/normal_604cdb5b00730.pdf
- https://wezusutuxalik.weebly.com/uploads/1/3/1/6/131637092/8f6c20a864.pdf
- https://cdn-cms.f-static.net/uploads/4372378/normal_6023fb320131c.pdf
- https://cdn-cms.f-static.net/uploads/4369797/normal_604c9e5299e12.pdf
- https://jukuxalubena.weebly.com/uploads/1/3/1/4/131453985/kosix-juxeriz-refevitaziwesob.pdf
- https://cdn-cms.f-static.net/uploads/4448746/normal_603cc9703d8f1.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/dc2d834b-c4f7-4861-875b-4492c769e240/86799385511.pdf
- https://2386e270-bd20-42c1-b3e5-1ba7eaa1d68d.filesusr.com/ugd/b4f0c6_cb5e52b9874c45b99862532fe5f74cf6.pdf?index=true
- http://sofopemesojume.epizy.com/kubikojuvavujop.pdf
- https://uploads.strikinglycdn.com/files/a7d3d9d3-74e1-4e56-92e4-62d25af1692a/keurig_k_cup_holder_replacement_bed_bath_and_beyond.pdf
- http://jipudovisubu.rf.gd/c_lambda_template_parameter.pdf
- https://uploads.strikinglycdn.com/files/4aa1053b-5704-4f43-afaa-54509ece501e/pafadaludewapatibajositow.pdf
- https://41c240d9-b4af-4f88-8fa4-2a41cce3a287.filesusr.com/ugd/01bc73_c25ea6515bcc42468e7c0b10e46de7e2.pdf?index=true
- http://tesusaruva.epizy.com/metformin_causes_bubbles_in_urine.pdf
- http://gitobunubi.epizy.com/frases_nominales_en_ingles.pdf
- https://d86ad34a-7df2-4f47-937b-a12ab5abc0fa.filesusr.com/ugd/8cbfce_79472db4398b49acbdd214739c31a7d3.pdf?index=true
- https://uploads.strikinglycdn.com/files/2d7d865b-aa5e-4880-b7ad-ddb23e622ed2/how_long_bradford_white_water_heater_last.pdf
- http://vulamexi.rf.gd/dikibulijogiwosoko.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001296c.bin945631315962f2fc43552cf43aa1becc9c9f0401c49a57ca8c604d9c04123c6e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1296C | 5064 bytes |
font_01_sfnt_off00013a7b.bin4f4409febf58c7c5d8118e84a95ec2e51b9a85cc39d36a3bd164e0e461fdf7bc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13A7B | 14064 bytes |
font_02_sfnt_off000165bb.binb50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x165BB | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.