MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which point to other PDF files, suggesting a link farm designed to manipulate search engine results or distribute malicious content. The presence of the ClamAV detection 'Pdf.Phishing.Trojan-d2568dad23a94d95' and the ML classifier flagging it as malicious strongly indicate a phishing or trojan distribution attempt. No scripts were extracted, but the structure implies the document's primary purpose is to redirect users to potentially harmful external sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/wix?keyword=starship+troopers+traitor+of+mars+imdb+parents+guide
- https://cdn-cms.f-static.net/uploads/4404297/normal_60205471b5923.pdf
- https://nefosedinipal.weebly.com/uploads/1/3/4/6/134698739/jekafetaxumite.pdf
- https://cdn-cms.f-static.net/uploads/4408464/normal_600fc24e80cda.pdf
- http://alisaborodaenko.design/download_getty_images_without_watermark_2018b0qvf.pdf
- https://cdn-cms.f-static.net/uploads/4458163/normal_605193fe2ba04.pdf
- https://static.s123-cdn-static.com/uploads/4424696/normal_5fec5a372f23f.pdf
- https://kojaresojew.weebly.com/uploads/1/3/4/3/134312518/jugobaxip.pdf
- https://cdn-cms.f-static.net/uploads/4462075/normal_5fd296f643a00.pdf
- http://hq-cleartv.info/80101581714ijll.pdf
- http://m-ryanaf.site/20335494709ikkyg.pdf
- http://golosa-spasibo.ru/diseased_giant_rat_dnd_5e0ya25.pdf
- http://milesnires.xyz/formal_job_offer_letter_template_uk26oze.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/67bb5187-2026-44cf-b6f9-511aa539fe53/zutalixib.pdf
- https://uploads.strikinglycdn.com/files/c959b046-7a06-4994-802b-a72beb890b96/tefaj.pdf
- https://uploads.strikinglycdn.com/files/b9959b7d-4648-4dfb-9f40-371f8fd26905/the_worship_sourcebook_2nd_edition.pdf
- https://uploads.strikinglycdn.com/files/d3828750-da78-4264-9f4c-3de9936934bc/giderexudurigegajupiv.pdf
- https://uploads.strikinglycdn.com/files/469cd216-2ee0-49e7-bbc3-e8f365256faa/shocker_rsx_paintball_gun_review.pdf
- https://uploads.strikinglycdn.com/files/69824a60-7538-4ab6-b413-a1c161603a57/corporate_performance_management_for_dummies.pdf
- https://uploads.strikinglycdn.com/files/6fde678e-72f3-48af-a1c1-d9de5633ebaa/fluval_406_parts.pdf
- https://uploads.strikinglycdn.com/files/d1ee9c88-6101-4f22-90ef-551741a8f146/singer_237_sewing_machine_made_in_france.pdf
- https://uploads.strikinglycdn.com/files/d8d27b30-616f-4498-bab5-8779dee29d25/39836397809.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000121e4.binbbf4443adb2194a81f2ac12e96fc3277a98e504a92763ddb2d8b2fdd0c645bdc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x121E4 | 5668 bytes |
font_01_sfnt_off000134f9.bin0241669b5d01547fd536c45268f79da3db406a1e711e0a729bfc83c5dc2f5b42 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x134F9 | 12988 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.