MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified as a link farm, pointing to various PDF documents. One of the primary URLs, 'https://soxebez.ru/award?keyword=basics+cctv+system+pdf', suggests a potential phishing or SEO manipulation tactic. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or distributing further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9964
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/award?keyword=basics+cctv+system+pdf PDF link annotation
- https://cdn-cms.f-static.net/uploads/4393763/normal_5fe64bf9b5008.pdfIn PDF document text
- https://bejokuwawij.weebly.com/uploads/1/3/4/6/134688199/tivasanunuxidax_gijoniti_fadural.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4393641/normal_604ef7b30dee6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4409813/normal_600f40e1783cb.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4449185/normal_5fd97099d5f7b.pdfIn PDF document text
- https://guzejanum.weebly.com/uploads/1/3/4/6/134681017/renib.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4495843/normal_60098fa9c7793.pdfIn PDF document text
- https://logifuvixejexa.weebly.com/uploads/1/3/6/0/136019385/gimagapovofop_vosabine.pdfIn PDF document text
- https://budaxopam.weebly.com/uploads/1/3/4/7/134711784/a81d731.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/naxozelozude/annexure_d_for_passport_format.pdfIn PDF document text
- https://s3.amazonaws.com/gonima/93886854201.pdfIn PDF document text
- https://acaa17bf-cf2e-4132-a9e9-810271eb8bc4.filesusr.com/ugd/ab5b4c_281a8ac1ffd647139b1e248f441ac6c7.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/radubozufiwo/7859107141.pdfIn PDF document text
- http://fepoxojosatomu.epizy.com/can_you_read_books_on_kindle_fire.pdfIn PDF document text
- http://mevuzulutifoxa.rf.gd/how_to_load_staples_in_staples_one_touch_plus.pdfIn PDF document text
- http://sogonuvusawi.epizy.com/various_forms_of_physical_exercise.pdfIn PDF document text
- https://s3.amazonaws.com/suxugipipolazog/kelley_blue_book_used_car_values_wikipedia.pdfIn PDF document text
- https://cd65756b-a9c7-4cca-9498-1747a6459195.filesusr.com/ugd/05eb20_8bbfb5242192438dbc7cf10ee223b9a0.pdf?index=trueIn PDF document text
- http://dujofaxuro.rf.gd/the_silence_of_the_lambs_book_synopsis.pdfIn PDF document text
- https://s3.amazonaws.com/nilititonawafim/fraction_word_problems_grade_7_worksheets.pdfIn PDF document text
- https://s3.amazonaws.com/muxozuvalubi/remove_clock_icon_android.pdfIn PDF document text
- http://fozagagubimamow.epizy.com/orbit_sprinkler_system_working.pdfIn PDF document text
- https://53f03ce6-db0b-4f41-9bfc-6956ba41e1f4.filesusr.com/ugd/727e0f_31f813a111364c0f80f63d0b5892cf43.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/garorowa/domain_and_range_of_exponential_functions_worksheet_kuta.pdfIn PDF document text
- https://3f46bf15-0a8c-4e80-b3e5-a2e3bf90e008.filesusr.com/ugd/8e6e76_6d508f92d6704f60851d1b61c0943f53.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/kisimujuk/the_veldt_audio_with_stephen_colbert.pdfIn PDF document text
- https://d09251a9-b09e-4077-8ccb-24037f005f7b.filesusr.com/ugd/a6ce17_f0ef533617104b588871e888e4569571.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f665.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF665 | 5384 bytes |
SHA-256: 95c6818c13d1f6f6374111ed2a036f9ec486e0ebe91cf74baf88cfd8304c5281 |
|||
font_01_sfnt_off000108b8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x108B8 | 10708 bytes |
SHA-256: a025562e077eed782d014aa97347febfcc64f98795742569a7871055b512650d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.