Malware Insights
The PDF file contains a large number of external links, many of which appear to be part of an SEO link farm. One of the extracted URLs, 'https://leonvi.ru/123?utm_term=app+to+watch+anime+on+android', is directly associated with the PDF's content and is flagged as unknown reputation. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, and 'ML_NYX_PDF_MALICIOUS' along with 'CLAMAV_DETECTION' strongly suggest malicious intent. The document body, though heavily obfuscated, contains metadata related to the authoring application and creation date, but no direct instructions or lures are discernible.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/123?utm_term=app+to+watch+anime+on+android PDF link annotation
- https://cdn.sqhk.co/tivuzofep/5mhiL65/gapusolifudesapobi.pdfIn PDF document text
- https://cdn.sqhk.co/mutexeze/ahdgeXj/inside_out_and_back_again_chapters.pdfIn PDF document text
- https://rugibabolunape.weebly.com/uploads/1/3/1/4/131454120/75023.pdfIn PDF document text
- https://nufulukoveta.weebly.com/uploads/1/3/4/7/134700555/nenuk.pdfIn PDF document text
- https://cdn.sqhk.co/botonerepap/jhs8haT/tukogaxi.pdfIn PDF document text
- https://cdn.sqhk.co/jarixizotib/gj7GjbE/five_nights_at_freddy_s_4_games_lol.pdfIn PDF document text
- https://guxadudupis.weebly.com/uploads/1/3/4/7/134751999/zefuvog-pukofilosubi-demutupilibud.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/lotibabakuj/collins_gcse_biology_revision_guide.pdfIn PDF document text
- http://kazaxese.epizy.com/15583839572.pdfIn PDF document text
- https://s3.amazonaws.com/lizuseguwix/mimenuruvulusejikab.pdfIn PDF document text
- https://s3.amazonaws.com/jixerubowi/25555699913.pdfIn PDF document text
- https://d80868e2-5d34-4dda-9345-0396294a35aa.filesusr.com/ugd/f9fac6_1f088dba82c14635b35c1d1bbf8e29bd.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/zoluwivebiro/942296732.pdfIn PDF document text
- https://s3.amazonaws.com/mubemutolewe/avengers_assemble_game_free.pdfIn PDF document text
- http://puribobelumisi.rf.gd/cecilia_meireles_download.pdfIn PDF document text
- https://s3.amazonaws.com/rujimidujek/16139057082.pdfIn PDF document text
- https://27a83426-c768-4525-a63d-b5b732cca755.filesusr.com/ugd/28b3f7_84d8dffcb8784d97ad5d604d8a83d271.pdf?index=trueIn PDF document text
- http://magajavopisili.epizy.com/13900174192.pdfIn PDF document text
- https://s3.amazonaws.com/jefazaxal/bollywood_songs_320kbps_pagalworld.pdfIn PDF document text
- https://s3.amazonaws.com/titugome/sony_xplod_car_bass_box_200w.pdfIn PDF document text
- https://s3.amazonaws.com/mupukesunobaga/63279019714.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001bb2f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1BB2F | 5184 bytes |
SHA-256: f4c00681da6432c0c52519dbd691f3cd95e5f475e4e9010499ae64cc62c11b13 |
|||
font_01_sfnt_off0001ccb7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1CCB7 | 11340 bytes |
SHA-256: d7d3a3373802ea01454fc2b8895d2721e1e3e0f99215f0df138ed0f9cd86e1e0 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.