MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, with one suspicious URL pointing to 'pelibifir.ru'. ClamAV and ML heuristics also flagged the file as malicious, specifically as a phishing trojan. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic suggest the primary goal is to redirect users to malicious or deceptive content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/123?utm_term=diabetes+australia+treatment+guidelines
- http://kopumiwabetare.66ghz.com/dark_mode_gmail_app_android.pdf
- http://xujakebetutusu.22web.org/conversion_of_galvanometer_into_voltmeter_experiment.pdf
- http://lozipazom.sportsontheweb.net/53018552230.pdf
- http://zefujixa.mywebcommunity.org/assembler_language_with_assist_and_assist_in.pdf
- http://dutarotanazosuv.medianewsonline.com/synchronous_motor_theory.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/13b27327-cafa-442c-8dfe-da639e830254/my_son_the_fanatic_movie_stream.pdf
- https://b00f38ea-0d13-4519-ab0f-1253f0d03ca0.filesusr.com/ugd/289c5e_4a2a369c3ba44b6b9b64bbd741694c40.pdf?index=true
- https://s3.amazonaws.com/jefobexapulow/18351448034.pdf
- https://s3.amazonaws.com/gitipelut/birthday_card_cake_free.pdf
- https://uploads.strikinglycdn.com/files/ea3ecd2b-3616-42ee-8636-7e8e2ae15f7f/slingbox_m1_wireless_setup.pdf
- https://38e81cab-313f-462b-917d-d566bf782aa4.filesusr.com/ugd/36aba1_a924a3ccbc824b2088423e486a278f74.pdf?index=true
- https://s3.amazonaws.com/tadevewuju/qradar_dsm_guide_7._3._1.pdf
- https://s3.amazonaws.com/jivamubug/pedima.pdf
- https://uploads.strikinglycdn.com/files/ac0d212c-1126-4a43-9fb6-632e1cdfbc26/how_can_i_track_my_american_eagle_order.pdf
- http://gamanavaje.epizy.com/philip_kotler_marketing_management_free_download.pdf
- https://59548cc9-d6a6-4b2e-bd73-2bfb7290c7b5.filesusr.com/ugd/3fd21f_2eca7557226f45c9806adf94c3df3c51.pdf?index=true
- http://dimizisunope.epizy.com/multiplying_decimals_worksheets_grade_8.pdf
- https://s3.amazonaws.com/rabewiruzitewa/shine_a_light_banners_song.pdf
- https://2d2b1dae-c014-4902-97e6-c3f1d56915cd.filesusr.com/ugd/70e5f7_98629a2b28c049d0b18068fd6a905505.pdf?index=true
- https://6478d21b-237c-41b5-add8-96d7b9819624.filesusr.com/ugd/c7ef1a_ca88153051f34889aac7065a4f3a58e4.pdf?index=true
- https://db6d201d-bdff-4648-9982-d9cfaac7639e.filesusr.com/ugd/98857b_a88830497c5a4fabb742891f5e24d8b4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e162.binb3c55c56f35de044e010c3201ba79de9628dec717424c783b791e9e0ac8453ac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE162 | 5284 bytes |
font_01_sfnt_off0000f343.bin5e44924fda43899361c8d39345ff9877c080252ac90b6e5e7410a9795a30b87f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF343 | 12096 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.