MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://fokemale.ru/strik?utm_term=how+to+do+code+freeze+frame+on+imovie PDF link annotation
- https://cdn-cms.f-static.net/uploads/4503309/normal_606e9aaeda8a7.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4389570/normal_600b454fa7637.pdfIn PDF document text
- https://cdn.sqhk.co/jaxubefe/iegiDib/ninja_air_fryer_xl_manual.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4455376/normal_6058d73d3f1cb.pdfIn PDF document text
- https://ruzamugube.weebly.com/uploads/1/3/4/0/134040566/lepatojadila.pdfIn PDF document text
- https://cdn.sqhk.co/zadoweferoxe/hiicje2/hero_rescue_mission.pdfIn PDF document text
- https://wosubazaroden.weebly.com/uploads/1/3/0/8/130813518/siwovedakiral_pexarenuxorigu_xodabuxigog_zofadut.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4415754/normal_5fdc55ae7bb15.pdfIn PDF document text
- https://gakatonigi.weebly.com/uploads/1/3/2/6/132681340/vesezupinon.pdfIn PDF document text
- https://cdn.sqhk.co/metusoteliza/ehjkjif/smart_balance_butter_spread_nutrition_facts.pdfIn PDF document text
- https://cdn.sqhk.co/zaliroded/iIrotja/last_survivor_last_runner.pdfIn PDF document text
- https://cdn.sqhk.co/fudikuzi/jtojjje/h_m_rolling_stones_t_shirt.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/cc90d0cf-a5ff-4de3-b2b5-debd63b227b3/39621419170.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/641b49ee-69e8-4f35-a79f-3419df538f3f/sotiligaretonemepupuf.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5a023fdf-7a7f-4530-a618-cabad5acc7c9/duwizaliw.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/df360222-247b-490d-a922-c9f10ac1b514/south_carolina_drivers_manual_audiobook.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/51a9da43-9d81-4ca0-86d2-10047e937223/does_murano_have_transmission_problems.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/880e46cd-1328-450d-9a45-f90e228eb43e/larupekuxixemepimu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/369ba858-3f04-490c-8465-457672554d0f/2297258875.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1b3fae70-e547-4022-b2c1-323631d5fbdf/sexual_reproduction_definition_easy.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8f30091e-9942-4692-95eb-f196c8a49c16/revemo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e22e062a-177a-40a6-a44d-a226330fc771/the_reason_why_is_that_or_because.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8327590a-e306-4a3a-8415-d3c0eecced51/kazizejejeviwitumibanepap.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fa476d7e-400e-470c-85bc-75273093576b/68068911212.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000124de.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x124DE | 5120 bytes |
SHA-256: 2817ea270c50016bbe398c970974a785d0c7733247144f6c5e8d0449d8fe0c1c |
|||
font_01_sfnt_off00013652.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13652 | 11048 bytes |
SHA-256: 31231629a1dbef76dec8463c99db1554eb95488fec01c52ff1d49b397c102d5a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.