MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/strik?utm_term=capitulo+4a-4+asking+questions+continued+answers PDF link annotation
- https://gojemafofapuvog.weebly.com/uploads/1/3/2/6/132681271/9351978.pdfIn PDF document text
- https://zopofaxomape.weebly.com/uploads/1/3/4/3/134372760/e8852cbe410.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/9f19a774-d927-47b9-91f4-d19b2942835b/abaqus_cae_users_manual_6.13.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f0bafef3-d342-4664-827d-761b73f91bec/active_and_passive_voice_rules_chart_download.pdfIn PDF document text
- https://s3.amazonaws.com/gawabog/fluticasone_propionate_davis_drug.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/830a75a1-757f-41d3-8651-5071b236f9f9/how_to_fix_samsung_remote_control.pdfIn PDF document text
- https://s3.amazonaws.com/gurafoga/what_does_the_bible_have_to_say_about_fear.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0c92fa59-00f6-4425-8e33-7a3f86146401/brother_tn-420_drum_light.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4ae5964d-4285-441a-94df-cf647ac6a6a7/vugame.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3dd14cfe-37f5-48a4-b75d-2bbbcce5ecb5/what_size_is_30_by_40.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6658f125-d785-4eae-81c5-3c5469a58eaf/roduk.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/97abf072-7950-46be-8373-44a294a2cb93/lopukudamebugumu.pdfIn PDF document text
- https://s3.amazonaws.com/setigafat/wibaxufo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a95ccb13-24b6-4ee6-9451-05cd4ef629bf/65207892499.pdfIn PDF document text
- https://s3.amazonaws.com/kagedatabujo/how_to_work_afterglow_headset_ps4.pdfIn PDF document text
- https://s3.amazonaws.com/tonisefoteka/what_is_critical_thinking_skills_in_the_workplace.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/57ae0365-b561-4c90-8194-4dd0f1049b96/73379810228.pdfIn PDF document text
- https://s3.amazonaws.com/bufipevuril/artifactory_rest_api_latest_artifact.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b1fb19c7-a2f2-4642-90b3-9ac355d59b2b/detoxe.pdfIn PDF document text
- https://s3.amazonaws.com/pukiza/wunotilesuforanaxosixuw.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/61c28a66-48f6-4575-8060-72d4dc9ee6c1/timeline_template_2nd_grade.pdfIn PDF document text
- https://s3.amazonaws.com/wexoteluwag/indiana_jones_sheet_music_french_horn.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4a076aee-2541-474c-8c21-04d33c912ff4/11152988229.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f671.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF671 | 5548 bytes |
SHA-256: d998e8b9baafb71d80f0c33f4f2b3c158b84711bf6c62afdef653f0042110a29 |
|||
font_01_sfnt_off00010975.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10975 | 11056 bytes |
SHA-256: 42d3de4645dcc73687e115c2e24314c8bb7ac99febf3796c254bd85a6071d06f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.