MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with one prominent URL pointing to a suspicious domain that appears to be part of a link farm. ClamAV and ML classifiers indicate malicious content, specifically identified as a phishing trojan. The document body, though heavily obfuscated, contains keywords related to public administration and strategy, suggesting a lure for phishing or further payload delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/award?keyword=administra%25C3%25A7%25C3%25A3o+p%25C3%25BAblica+pdf+estrategia
- http://copyright-rules-help.com/83943596321nbgtn.pdf
- https://cdn-cms.f-static.net/uploads/4495837/normal_6048aa6131be7.pdf
- https://cdn.sqhk.co/rapowipijes/jaii1Vd/mandalorian_bebe_yoda_mobile_wallpaper.pdf
- https://cdn.sqhk.co/tarozawowe/Fgdiejj/jibibomigakezolosemep.pdf
- http://lnstagramcentre.net/john_lewis_radio_controlled_alarm_clock_instructions39paf.pdf
- https://cdn-cms.f-static.net/uploads/4392474/normal_5fd78ebe48905.pdf
- https://cdn-cms.f-static.net/uploads/4380674/normal_6049a4c8b4c49.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://8e6fe9cb-6e01-49b8-a8bf-add1d7538daa.filesusr.com/ugd/4e948c_b9545d807ca84728946cf693b9eed611.pdf?index=true
- https://d8d691c7-cf48-432b-bece-a54604b57851.filesusr.com/ugd/1e3a4b_1a93e3a04aca4a8f931ed275b320c885.pdf?index=true
- https://s3.amazonaws.com/puretulenuza/jiwuxodit.pdf
- https://s3.amazonaws.com/sajatofubote/ketogenic_diet_book_free.pdf
- https://s3.amazonaws.com/wudibirewuduto/pomimonuv.pdf
- https://d8acad56-eb9a-42d1-a06c-a695c5b02328.filesusr.com/ugd/0ad6c7_eecfe20ae0354da7b422d06e09e2798e.pdf?index=true
- https://s3.amazonaws.com/kukupunopedon/sinupoxosor.pdf
- https://s3.amazonaws.com/zupenafud/52893732757.pdf
- https://aa5f33e9-793b-4807-a257-9eac84d314d0.filesusr.com/ugd/aa57b2_43d2f0ac2bae44a6a136f133365b4b03.pdf?index=true
- https://s3.amazonaws.com/sabegokek/walaviraju.pdf
- https://s3.amazonaws.com/genedonapubefe/what_to_do_if_paper_shredder_is_stuck.pdf
- https://s3.amazonaws.com/kukazowox/20850442222.pdf
- https://c140f178-ee45-427e-91fe-a3c5f821f67e.filesusr.com/ugd/ebc5f9_3ccc599188c34c64897c939fae6be009.pdf?index=true
- https://s3.amazonaws.com/xeroguru/lowdermilk_beach_red_tide_report.pdf
- https://s3.amazonaws.com/juliziwojatige/telefono_para_reportar_alumbrado_publico_zapopan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dd03.bind3e3e90f5e5ea3d8a0dc76ffbd860192539c418f962dc86bc0588fdc943dd751 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDD03 | 6220 bytes |
font_01_sfnt_off0000f104.bin0bd0ffcf292d17986282c0f01a7b0cfbb74d00b5c130826d7e4b03629bc3923e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF104 | 11600 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.