MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/wb?keyword=their%20eyes%20were%20watching%20god%20quizlet%20ch%205 PDF link annotation
- https://cdn-cms.f-static.net/uploads/4379034/normal_601eaa9a4db1a.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4381320/normal_603c1ba1bcbbb.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4450728/normal_603d44730f2e1.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4427821/normal_5fc655fa82e1e.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4371809/normal_60525b0c263a9.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4460449/normal_606e61fcaf8e2.pdfIn PDF document text
- https://gikenizebos.weebly.com/uploads/1/3/4/7/134706738/2650842.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4386593/normal_5fe4089ecd1ca.pdfIn PDF document text
- https://bugituwixumanuz.weebly.com/uploads/1/3/4/7/134722584/guliju.pdfIn PDF document text
- https://static.s123-cdn-static-d.com/uploads/4369165/normal_60b002196be61.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4380699/normal_601a4adc578a5.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/c38ab6d9-456f-45d5-aa96-49e50a479cf4/9445991665.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1169ded3-027a-4aaa-9fb4-5f3bef510ef6/25692341677.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fb80b5f8-1d50-4738-b2ac-1133a35fa909/how_do_i_reset_my_iproven_thermometer.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fb272ee3-c511-478e-905b-dae9f51120bc/ps_gold_headset_mic_not_working_on_pc.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/596fbda1-0184-4da2-8416-bf8166b22ba2/835287547.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/55334f39-dee1-4065-9826-e907dec4dfe3/bepipelirexonitimulizo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/435629a3-5612-49b7-852d-4e65fae4f935/notasoduvinole.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b1814a45-a76a-45ab-9b02-ef6bb9fa68b1/can_you_breed_in_pokemon_crystal.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/38949075-b21d-4f89-964b-4f7540664fcb/painful_red_bumps_on_skin.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5acb8b7f-59f7-473f-b2c5-1b63565b4bbe/8670456190.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b44580cf-5690-4ccd-bf01-7ff26155d09c/hp_laserjet_1100_repair_manual.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000da7c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDA7C | 5644 bytes |
SHA-256: 389b8bfd9f1c8b51ec2a2566a4ed62e3cc3acd50f4e67ebd3555e201bed71d59 |
|||
font_01_sfnt_off0000edc1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEDC1 | 9980 bytes |
SHA-256: ad12730a3da59f2671068e170b6b94286ee713023a8d5ced032cf3a370966db1 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.