MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a heuristic firing for a link farm and an embedded URI pointing to a URL that promises free gems for a game. This suggests a phishing or scam attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, likely to redirect users to a malicious site or download further payloads.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/wix?keyword=dragon+mania+legends+free+gems+no+survey
- http://sobuvide.mygamesonline.org/pseudomonas_spp.pdf
- http://jiwapadenejeza.getenjoyment.net/how_does_google_maps_traffic_data_work.pdf
- http://godezigupo.mywebcommunity.org/todukofinogugekid.pdf
- http://xomutukegadoj.mypressonline.com/samsung_aqua_jet_vrt_smart_care_washer_parts.pdf
- http://sowoxapexemex.sportsontheweb.net/rodaxojunowop.pdf
- http://ramuwesitavoz.mywebcommunity.org/48314734902.pdf
- http://zobotalemogi.sportsontheweb.net/vajisukuvetosi.pdf
- http://xitabijasava.getenjoyment.net/65423433406.pdf
- http://jetinaxisodew.mypressonline.com/genetics_grade_12_notes.pdf
- http://lixodamevurobar.mygamesonline.org/antigenic_shift_and_antigenic_drift.pdf
- http://tevituvodejifep.mywebcommunity.org/48948280129.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/kobivimelelo/r_kelly_tp2.com_free_mp3_download.pdf
- https://s3.amazonaws.com/jajoxulabojaso/geebung_weather_report_today.pdf
- http://kakavogulogij.onlinewebshop.net/dabuxixogofe.pdf
- https://s3.amazonaws.com/serogajugomiji/roriposilukesipaxibusom.pdf
- https://3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com/ugd/16a96a_54b8efe1f00d46b89021ec21515194bb.pdf?index=true
- https://6d8b2927-5c4d-40df-b593-c6bd35e19528.filesusr.com/ugd/1adac8_c202771cb3724ac5b906b34b14a0d46f.pdf?index=true
- https://s3.amazonaws.com/pibajuwi/printable_baseball_box_score_sheet.pdf
- https://9de673a2-3b8e-40eb-bbf5-c0ad8e71a3da.filesusr.com/ugd/bd5c68_4d7d00bd9b204103882aba56ff2d86fc.pdf?index=true
- https://s3.amazonaws.com/zunaduxa/catequesis_semana_santa_para_nios.pdf
- https://s3.amazonaws.com/davubewu/sotukovagoka.pdf
- https://ed4d48c2-14ea-47f5-a89a-b82193587323.filesusr.com/ugd/8ce377_9872b344534b4ce88daea350e16540ae.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cda8.bin9c8ffd55e7c96655c806441d68120bceebde6edd1fd477f791937cd89f015d66 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCDA8 | 5388 bytes |
font_01_sfnt_off0000dffa.binba2e673e4e2520b4863dbf790c2a653dd15963cc735a0c87c87808440aa4c451 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDFFA | 10644 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.