MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with a critical heuristic firing for a 'PDF_SEO_LINK_FARM' indicating a mass of external links. One of the primary URLs, 'https://xezojetit.ru/strik?utm_term=what+is+the+alternative+to+apple+time+capsule', suggests a lure related to Apple Time Capsule alternatives. The presence of XFA forms and a high ML score further support malicious intent, likely for phishing or distributing further malware.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
XFA form low PDF_XFAPDF uses XML Forms Architecture — can contain script logic
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/strik?utm_term=what+is+the+alternative+to+apple+time+capsule
- http://copyrightshelpcenter.com/fomugemx5tv4.pdf
- https://gixefizavemo.weebly.com/uploads/1/3/4/1/134108956/2189382.pdf
- http://pravagims.net/vekobozokipunuzibesogiljxya.pdf
- http://zebarugusi.22web.org/reformation_heritage_kjv_study_bible_online.pdf
- http://goproonly.com/566249209102g4vd.pdf
- https://bosamekuxukis.weebly.com/uploads/1/3/4/6/134672370/3567278.pdf
- http://helplnstagramoffice.com/hardware_id_acpi_smo8800gbge8.pdf
- http://servisvds.ru/the_heart_of_darkness_by_joseph_conradhz8tc.pdf
- http://trydouche.xyz/21994171838ejlx8.pdf
- http://namsinc.info/miniature_german_shepherd_puppies_uk6qoco.pdf
- http://logusubunovad.22web.org/adverbs_worksheet_7th_grade.pdf
- https://lobobofu.weebly.com/uploads/1/3/4/6/134680821/devefexe-gapibosudi-binage-gidebetuxexew.pdf
- http://instahelpforbusiness.com/consider_the_frame_shown_in_figurejrxoh.pdf
- http://sefobadivura.iblogger.org/13063921450.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/5036df41-9bcb-434e-84de-934c206b2a48/cut_patricia_mccormick_genre.pdf
- https://uploads.strikinglycdn.com/files/1c64f975-21e7-4c5c-95f5-7d23314d72fd/maytag_bravos_xl_washing_machine_reviews.pdf
- https://uploads.strikinglycdn.com/files/f51cc85b-1356-496f-978f-497f51de2c3b/intent_to_claim_disability_support_pension.pdf
- https://uploads.strikinglycdn.com/files/b62ddc60-65cc-4468-8d82-ba9646b91c35/zixiwizafizize.pdf
- http://difugarulid.epizy.com/petikik.pdf
- https://uploads.strikinglycdn.com/files/774dea79-15cd-4fa8-8332-3ded6e8cd645/hp_p1606dn_factory_reset.pdf
- https://uploads.strikinglycdn.com/files/d8543f1a-51be-44c7-899f-91145cc7fbcb/ends_based_ethics.pdf
- https://uploads.strikinglycdn.com/files/7b6722a2-47e5-44ab-a54a-8a77ce391ea6/sininoganaxuji.pdf
- https://uploads.strikinglycdn.com/files/50328874-9779-4462-bf8e-77e92ca941e3/pavilixuwe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fc26.bincef1bc24ac086ec0f9cca94d9725b5091dcc62269cdba1f9864bb1a6bad0f58e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC26 | 5244 bytes |
font_01_sfnt_off00010de1.bin0f5c82e69a9397971e20f8ae634f8851897435eb085e68ef4d32a8a3a3f980a9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10DE1 | 10948 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.