MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many hosted on disposable domains, suggesting a link farm or SEO spamming operation. One prominent URL, 'https://midufefew.ru/strik?utm_term=dd-wrt.v24+mini_generic.bin+download', appears to be a lure for a software download. The ML classifier strongly flagged this PDF as malicious, and the heuristic firings indicate a link farm designed to distribute content, likely malicious, through numerous external URLs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/strik?utm_term=dd-wrt.v24+mini_generic.bin+download PDF link annotation
- http://pofuxubilet.sportsontheweb.net/akhund_darweza_baba.pdfIn PDF document text
- https://gulipuzajetag.weebly.com/uploads/1/3/5/3/135397689/dilinenibe_lubaweza_wegobu.pdfIn PDF document text
- https://dovapudatanul.weebly.com/uploads/1/3/5/9/135985540/6553507.pdfIn PDF document text
- http://somixewavado.sportsontheweb.net/john_deere_js63_diagram.pdfIn PDF document text
- http://lavka-karamel.ru/tomutudokiwacx646.pdfIn PDF document text
- http://zumewidife.mygamesonline.org/possessive_adjectives_explanation.pdfIn PDF document text
- http://dreamingdeveloper.com/8716091694zz934.pdfIn PDF document text
- https://fusofopafufet.weebly.com/uploads/1/3/5/2/135294951/sogaritedofudixe.pdfIn PDF document text
- http://changepass.online/ukulele_strumming_patterns_4_4d4fg6.pdfIn PDF document text
- http://medgaj.com/27228532492oc0u1.pdfIn PDF document text
- http://goxamid.mypressonline.com/72649430506.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://uploads.strikinglycdn.com/files/0e97fc42-18fb-4221-99c8-df0f683f4cfd/is_it_legal_to_marry_two_wives.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1f28fc80-c0db-4aa7-a7e2-791cdce1d3a6/who_animated_one_punch_man_season_1.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/88d00f1c-b5f2-4ea8-b486-d991df6876d2/nalonulivixewel.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/469190ba-751b-42e1-b509-69f69a5138d0/metamorphosis_kafka_movie_online.pdfIn PDF document text
- http://zugepoguj.onlinewebshop.net/english_aptitude_test_questions_and_answers_free_download.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/63bd91a6-71fe-4c15-b3f0-b5b2b49ed5c6/how_to_fit_integrated_dishwasher_door_bosch.pdfIn PDF document text
- http://rijonitapadon.myartsonline.com/cisco_4742hdc_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9148ddfa-c450-439f-bcba-b036467d088c/guess_brand_logo_level_212.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b56fbc0d-64d1-44fa-ad2a-867028ffb9c1/physics_assignment_class_9_answers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/feb99536-c655-4152-9395-1d8596416ab7/samsung_55_inch_qled_tv_weight.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2919e78c-a5a9-48ed-a365-8be53c7e6868/the_gospel_of_thomas_youtube.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1f6fdc60-dc64-4759-bc0a-cff9a3840839/2010_lexus_rx_350_cargo_space.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fb29.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFB29 | 5472 bytes |
SHA-256: 9bffe208506e11b11056e9ac5a0aad145e2e948bf71ae1107ae4188413186800 |
|||
font_01_sfnt_off00010ddb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10DDB | 23128 bytes |
SHA-256: 9bcae257099423bad617c5a023ed56f47102754cd7711d1416c55856fd41c9c7 |
|||
font_02_sfnt_off0001425e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1425E | 4324 bytes |
SHA-256: 0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.