MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM', suggesting a malicious intent to manipulate search engine results or redirect users to malicious sites. The ClamAV detection and ML classifier further support its malicious nature, classifying it as a phishing trojan. While no scripts were explicitly extracted, the presence of numerous URLs indicates a likely attempt to download further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/wix?keyword=acls+experienced+provider+manual+pdf+download
- https://cdn.sqhk.co/vawupemowa/7s4IjiO/binonepo.pdf
- https://cdn.sqhk.co/tinulafi/aiaFNhH/zenozinoga.pdf
- https://fevebelok.weebly.com/uploads/1/3/4/0/134012800/datadafezotu.pdf
- https://pudosibax.weebly.com/uploads/1/3/5/9/135964381/govarukevosetit.pdf
- https://notaxivarem.weebly.com/uploads/1/3/4/6/134633458/vikuto.pdf
- https://cdn.sqhk.co/nukuzulu/N2Uwqgj/84739910767.pdf
- https://vubufuzavedorav.weebly.com/uploads/1/3/4/7/134766784/dawon.pdf
- https://cdn.sqhk.co/letarezetap/BgfBgji/jidetur.pdf
- https://cdn.sqhk.co/rarinuva/mzjharC/brazil_champion_of_the_american_cup.pdf
- https://tutemedoz.weebly.com/uploads/1/3/2/8/132814241/zekiloposusedu_marelapowenukol.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://zevebetuj.epizy.com/59440591045.pdf
- https://9cf93ecd-64ee-4ad6-afcc-f350577a7522.filesusr.com/ugd/c4dbd3_ac3463061b24422389d8c0ff21896e72.pdf?index=true
- https://443275ec-395d-4f86-84c9-2ed7a250e117.filesusr.com/ugd/7d471d_032153d3a36c403d85db10c13baabce4.pdf?index=true
- https://9334512a-4df1-45dc-8804-f0fa1d9e2a3d.filesusr.com/ugd/9466eb_1c4abfdd48f14605a070b21f6be4063c.pdf?index=true
- http://rokidibamufoduv.epizy.com/que_medios_de_comunicacion_hay_en_la_actualidad.pdf
- http://refuziw.epizy.com/solu_medrol_medication_guide.pdf
- https://8137cd1e-393d-4948-8193-eca935452849.filesusr.com/ugd/756799_522002cdb780448eb52e32627d61ce47.pdf?index=true
- https://09ec9d85-9312-4337-94d0-b84080e05f2e.filesusr.com/ugd/ac0094_ec8f75124dc7410f803614856b077859.pdf?index=true
- https://49b821e7-ee7e-41b4-809b-d0417b8c1ddf.filesusr.com/ugd/927743_1cfabb30a5e041a2a5b8dfa9abad5a03.pdf?index=true
- http://legofovivaxom.epizy.com/electricity_and_magnetism_guided_notes.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000faa6.bin1af3841ab6aed41362d401fa1a8a1b1d8466371ade3548d68ebf1a9abae1d8a6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFAA6 | 5512 bytes |
font_01_sfnt_off00010d64.bin5ee175a0d17429d41235da260c7e57fa8aa1bd4f46d0883f2d7ed47725a2364c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10D64 | 11908 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.