MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with a critical heuristic identifying it as a link farm. The primary URL, 'https://pelibifir.ru/award?keyword=les+histoires+dr%25C3%25B4les+de+toto+et+ses+devoirs+pdf', suggests a lure related to children's stories, likely to deceive users into visiting malicious sites. ClamAV detection as 'Pdf.Phishing.Trojan' further supports its malicious nature, indicating a phishing or trojan distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/award?keyword=les+histoires+dr%25C3%25B4les+de+toto+et+ses+devoirs+pdf
- http://xivazokib.medianewsonline.com/nourishing_traditions_pregnancy_diet.pdf
- https://nanopimage.weebly.com/uploads/1/3/1/3/131398258/3197720.pdf
- https://cdn.sqhk.co/gaduwifawide/JhjJhea/pibizuwodujomosajobudu.pdf
- https://cdn.sqhk.co/fadanade/ifOhdjf/tesis_de_administracion_de_empresas_venezuela.pdf
- https://xelegiri.weebly.com/uploads/1/3/4/4/134435730/betalel.pdf
- https://cdn.sqhk.co/sejixikerut/ihOhcji/e_pluribus_unum_stranger_things_recap.pdf
- https://cdn.sqhk.co/nedabuke/UheY2gf/english_stories_for_kids-_panchatantra_videos.pdf
- http://xufededubumavif.scienceontheweb.net/operations_management_certificate_programs.pdf
- https://cdn.sqhk.co/numisezopo/p3bkuAw/printable_handwriting_worksheets_for_4th_graders.pdf
- https://cdn.sqhk.co/besogevipadi/bMKjcwh/89724126605.pdf
- http://nibajafij.medianewsonline.com/bibasulivo.pdf
- https://cdn.sqhk.co/jovowosifo/3IQijT5/wudiparifi.pdf
- https://cdn.sqhk.co/sukonazukuv/jfgcifU/voice_recorder_samsung_galaxy_s8_plus.pdf
- http://betijeduw.getenjoyment.net/disixofekago.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://441768bb-9839-4df4-8f78-dd1233b527f6.filesusr.com/ugd/7e6080_09d62d4bcc2147c095598096486678ec.pdf?index=true
- https://0bdb67af-4c57-4a6e-9706-714cc80719f5.filesusr.com/ugd/fc840b_7408ba56a8a44317a75a967004b1786b.pdf?index=true
- https://11fe2947-f393-4df3-905d-f9f3730e834a.filesusr.com/ugd/b1b16e_b8dfeee35fb249eea51372ec6f3fc575.pdf?index=true
- https://d4078116-a2d5-466f-97e6-20d899f6ca30.filesusr.com/ugd/576447_ac02f244b69345d4bcd0e9b8d25b800e.pdf?index=true
- https://510b81f6-be4e-4e40-9acf-3f60af495837.filesusr.com/ugd/5f226b_147558aab0264a38a600082bd7b03c47.pdf?index=true
- https://6205d428-d5dc-494e-bbc3-e2236f9d811e.filesusr.com/ugd/6885a6_b2e9995496004c56b2e4f9a072435b0a.pdf?index=true
- https://4b002d3c-a55f-42ce-816c-238f848e88a9.filesusr.com/ugd/3398cc_0081ffaf172b422cbfa721e879c4731d.pdf?index=true
- https://709e7e89-b264-4d73-b757-064736ed86f1.filesusr.com/ugd/f523c3_bcec78e1b4994608add41c1819ba680f.pdf?index=true
- https://a21f0d7d-5fe0-4a99-a381-3b18266e0880.filesusr.com/ugd/6c313a_a07cb72c36e64197918e1918a7690570.pdf?index=true
- https://0298dc5a-7924-4276-8279-06452a5288da.filesusr.com/ugd/b30cf0_50f98b59a3db47cba1eef44546ddd250.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00016aa2.bine9afa273f76418c9ad037a840b1a9cfaa99ee0948a546c3063df2c3caefa664b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16AA2 | 5060 bytes |
font_01_sfnt_off00017ba4.binb678b40721fb87a2d1fedf7c20c5e073dbc332c185c773f788d6b1a06bccb952 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x17BA4 | 17828 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.