MALICIOUS
184
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.001 User Execution: Malicious Link
The file is a PDF containing numerous embedded links, many of which point to disposable domains and redirectors. Heuristics indicate these links are malicious and part of a link farm, suggesting a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly support its malicious nature.
Machine Learning
- Nyx PDF Classifier malicious score 0.9940
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=all+the+bright+places+libro+en+espa%25C3%25B1ol+pdf+gratis In PDF document text
- http://kisuvok.scienceontheweb.net/cisco_press_ccna_routing_and_switching.pdfIn PDF document text
- https://cdn.sqhk.co/bisozowinala/3mgeLGc/tesufasilojejowubema.pdfIn PDF document text
- http://lifolibi.sportsontheweb.net/esame_celi_a1.pdfIn PDF document text
- http://nifimoperokoj.medianewsonline.com/acrobat_standard_dc_convert_to_word.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4380675/normal_5fe518ac8c5b9.pdfIn PDF document text
- http://f1l3download.site/the_tempest_shakespeare_film_streamingmtrgg.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4459939/normal_60078bdc162c2.pdfIn PDF document text
- https://cdn.sqhk.co/bodevoposuji/gcidibl/todujiluxide.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4456122/normal_6013c3754cc52.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4464053/normal_5ff5dbcb57665.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4489722/normal_605c6a81b388c.pdfIn PDF document text
- http://xuxijosut.sportsontheweb.net/analytical_biochemistry.pdfIn PDF document text
- https://cdn.sqhk.co/wutalididow/0TqHmJe/black_short_hairstyles_2020_female.pdfIn PDF document text
- http://letnesil.xyz/51331296820sk4et.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4451755/normal_5fdde90082f0e.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4494661/normal_604b7737cb366.pdfIn PDF document text
- http://eushopvmn.site/beatles_sheet_music_for_piano0od95.pdfIn PDF document text
- http://uber-global.com/tom_clancy_books_in_order_goodreadslwnlh.pdfIn PDF document text
- http://natorg.fun/citroen_c3_picasso_workshop_manualwxltf.pdfIn PDF document text
- http://supariwepexafat.mywebcommunity.org/tovile.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/20d5bd9a-b84f-4845-b2fd-376e63cba719/99368682459.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/62a70d26-ba51-4f2a-9ce1-909d5f64f6dd/ganesetavapuruvipof.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7f5d4ba2-4723-4ac7-beb9-f579a910fc33/temple_of_seti_1_helicopter.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b78ca361-9014-4002-859f-d892ae8f70d2/jixatisemubazexi.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001eb8f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1EB8F | 5488 bytes |
SHA-256: 2fc4e0df12496b32da45019dc092cbfb39b422f66cff326fdf1636a12cb432b3 |
|||
font_01_sfnt_off0001fe71.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1FE71 | 5760 bytes |
SHA-256: eb700929294aaed2c16702a0260b5be1e9d41688e576da06c4f55143a21f15bb |
|||
font_02_sfnt_off000211bd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x211BD | 13416 bytes |
SHA-256: 6d432d3f3ae5a742428ccd1ad10de3f846cbfe5b1e2a7acfe814b94b07141560 |
|||
font_03_sfnt_off00023d81.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x23D81 | 16132 bytes |
SHA-256: 82f7aa4fef2cd90733ed84ef1d81c041b15990b82a49830089245cc24b586ea2 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.