MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF was flagged by ClamAV as a phishing trojan and ML classifiers indicated a high probability of maliciousness. The document contains a large number of external links, suggesting a link farm or redirection strategy. While no scripts were explicitly extracted, the PDF structure and numerous external URLs point towards a phishing or malicious redirection attack, likely initiated via spearphishing.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://seumenha.ru/strik?utm_term=cnn+news+today+live+tv
- https://cdn.sqhk.co/temisexezoda/icihih3/doon_defence_academy_admission_procedure.pdf
- http://yourlivehelp.com/68166565935o5z7w.pdf
- https://cdn.sqhk.co/golemejexeno/Ud0ijhC/8721857582.pdf
- https://jogojirodatu.weebly.com/uploads/1/3/4/3/134321770/0dde859.pdf
- https://cdn.sqhk.co/fumamimed/gfIgf89/depin.pdf
- https://cdn.sqhk.co/patagarinixa/agd3zih/hexa_1010_block_puzzle_game_apk.pdf
- https://weralafopibobal.weebly.com/uploads/1/3/4/3/134338927/bufiritetopijigu.pdf
- http://powajaxib.medianewsonline.com/deh-x4700bt_no_sound.pdf
- https://cdn.sqhk.co/numiwuzuwix/cWpDFsI/police_gun_sound_ringtone_download.pdf
- https://fotofewoxa.weebly.com/uploads/1/3/4/8/134849098/26e2c18e2e.pdf
- http://freefire-gifts.com/graco_duoglider_stroller_assemblyt27uf.pdf
- https://cdn.sqhk.co/rilowikapaz/b88Asjc/spin_tops_mod_apk_download.pdf
- https://cdn.sqhk.co/vavetiset/Tgghk9n/apache_tomcat_windows_10_64_bit.pdf
- http://redpandarecycling.com/the_principles_and_practice_of_auditing_puttickc603d.pdf
- https://cdn.sqhk.co/papusabefo/VH8jbgg/tumblr_aesthetic_wallpaper_yellow.pdf
- https://cdn.sqhk.co/rujiwujik/jdXBEoa/dash_cryptocurrency_wallet.pdf
- http://zifixoribe.scienceontheweb.net/27140120402.pdf
- https://cdn.sqhk.co/segenapiza/mT45SLE/jabanokupudotowugubuj.pdf
- http://bit7.top/9910206443vpadg.pdf
- https://majejuwusi.weebly.com/uploads/1/3/2/3/132303270/zusenamuxoguwuwes.pdf
- https://cdn.sqhk.co/rakuvonume/Fjay5I1/electric_train_station_near_me_now.pdf
- https://cdn.sqhk.co/xiladuxe/dhdaYge/47946228750.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://muvekalufisu.atwebpages.com/plant_biochemistry_agrimoon.pdf
- http://nopugorib.onlinewebshop.net/bonfiglioli_planetary_gearbox.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f6a9.bin5a1d258f9dc2c721276c983a93d9f2b301c0b8ebefbb9319a01b37b4e667d378 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF6A9 | 4884 bytes |
font_01_sfnt_off0001076e.bin55a8d005113f2043714ad8282384a1e948d527296c97c4168d787b9ef3272873 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1076E | 10920 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.