MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file exhibits characteristics of a phishing or link-farming attack. It contains a large number of external links, with a specific heuristic identifying it as a 'PDF_SEO_LINK_FARM'. The ML classifier and ClamAV also flagged it as malicious, indicating a high probability of malicious intent. The document's content, though heavily obfuscated, appears to be a lure related to 'maths revision notes'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/award?keyword=o+level+maths+revision+notes+pdf
- http://hamsterbig.com/big_little_lies_soundtrack_theme_songti0k2.pdf
- https://static.s123-cdn-static.com/uploads/4390680/normal_5ff422566a1b3.pdf
- https://cdn.sqhk.co/mamevugixej/jhfEgiN/dobomow.pdf
- https://static.s123-cdn-static.com/uploads/4375541/normal_5ff3ab57ead4a.pdf
- https://cdn.sqhk.co/novujarogoga/ehbSRje/french_manicure_nails_2020.pdf
- http://carinsusa.info/spectrum_math_workbook_grade_8_free92cvz.pdf
- https://cdn-cms.f-static.net/uploads/4458634/normal_60466343f049e.pdf
- https://cdn.sqhk.co/gafazakedoki/sieiibi/90570855622.pdf
- https://cdn-cms.f-static.net/uploads/4466135/normal_5fda7d4618510.pdf
- https://cdn-cms.f-static.net/uploads/4490140/normal_605d46eeba9fa.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://ae8c1479-5121-4009-b0ed-8259dbb1205b.filesusr.com/ugd/0aff45_db62d2cddb614e9ba63b0c0382d922cc.pdf?index=true
- https://3b044092-e341-4c69-a8e2-52b14fc1865f.filesusr.com/ugd/370021_852d623830d24c5f9fda22f62de96e8f.pdf?index=true
- https://1e16f6d7-285b-4488-bf07-d3e24ac90e20.filesusr.com/ugd/417718_7f370bd29be94068adc282896d0e348a.pdf?index=true
- https://7f1d4f38-7308-4051-b389-b8ed31312188.filesusr.com/ugd/e948c1_514f8d1ecb1e408ca7ce0127798bb8d8.pdf?index=true
- https://76df98a8-3e94-4eee-a6f5-23e1de06049b.filesusr.com/ugd/54c74c_f113abeb25dc453396be7ad9e657d14d.pdf?index=true
- https://781b76d0-895c-4d4e-90f3-491762fad171.filesusr.com/ugd/894952_13d31ba915964c5b82a05f290422b9e9.pdf?index=true
- https://47f996fd-8e57-4de1-b9ea-1bffeedbadfe.filesusr.com/ugd/1b0481_4bef68b6c92f4d168464ba67f2f87d53.pdf?index=true
- https://c245485c-e1a4-4c5a-9a2a-c465a95e53c8.filesusr.com/ugd/25f824_ee49af09a4224f319009daf908552ac5.pdf?index=true
- https://d992f69e-bc5b-430a-92d7-abfd66d0380b.filesusr.com/ugd/6f7357_0b991a793ebb41c59a623ba43de88ac3.pdf?index=true
- https://ebd73b9a-b255-48a5-b781-2bd84b483b4c.filesusr.com/ugd/956c05_caa5d10e07f34ed08707b9786b4701b8.pdf?index=true
- https://7f3356c1-ec1f-498a-9d41-5b36c14d87b7.filesusr.com/ugd/98d33d_9b2700ea91dc45f9b8d9137c7e816607.pdf?index=true
- https://f62823ea-e863-4eb7-bd7c-e3bac0139ff1.filesusr.com/ugd/8c639a_767b440d2a854966978c140610f56797.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d971.bin92e47729dd5b67dcadfec27e7d5ce0b714df77133c69044bbb7818a6c9ea43a7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD971 | 5368 bytes |
font_01_sfnt_off0000eb87.bin8e28b695678e1dec1d3e8ace209ce0c7ab7a7ca98dd4898ad81ae9a7a74ffa4f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB87 | 10380 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.