MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The sample is a PDF file flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. The PDF contains numerous external URIs, many of which point to disposable hosting or link farms, indicating a likely attempt to distribute malicious content or phish for information. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dugedepap.ru/strik?utm_term=rhythm+exercises+guitar PDF link annotation
- http://vurujupafowutox.mypressonline.com/tumupajomilisude.pdfIn PDF document text
- http://sunukekubuwaraj.22web.org/construction_company_safety_program.pdfIn PDF document text
- http://gupirigugorixuf.sportsontheweb.net/tawisufiv.pdfIn PDF document text
- http://reniloze.iblogger.org/nidazidopogu.pdfIn PDF document text
- http://bomepufibawil.scienceontheweb.net/wu_tang_saga.pdfIn PDF document text
- http://lovojat.22web.org/agriculture_chapter_class_10.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://romukebiguvux.rf.gd/brookstone_pocket_projector_slim_manual.pdfIn PDF document text
- https://8a833fea-7c9a-4d2e-a5a7-d3590f42a3e5.filesusr.com/ugd/9aab09_d5f5b1651270443589237f8fb8913fc0.pdf?index=trueIn PDF document text
- http://dobejevilorizu.epizy.com/64289124475.pdfIn PDF document text
- http://zenifipepodu.rf.gd/harry_potter_plot_half_blood_prince.pdfIn PDF document text
- http://pawegafed.rf.gd/samsung_55-inch_4k_smart_led_3d_tv_un55js8500fxza.pdfIn PDF document text
- http://jabaxuzadowepep.rf.gd/classical_sociological_theory_a_reader.pdfIn PDF document text
- http://zivumimilalak.rf.gd/dasezoraj.pdfIn PDF document text
- https://e7ba4f66-d023-404d-a355-a5b98970f127.filesusr.com/ugd/cac9e4_eae3515bb3f44e81b27a315f59fb33b9.pdf?index=trueIn PDF document text
- https://71a5d838-4e22-4830-8da1-7955ec3365f5.filesusr.com/ugd/f2f43e_7e4e979a23a8465bbfa4e0595dda8add.pdf?index=trueIn PDF document text
- http://natetiko.epizy.com/64907611245.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/72bd70a4-cfd4-4760-b2a5-6c420171953a/how_does_the_invisible_man_movie_2020_end.pdfIn PDF document text
- http://fekedavo.rf.gd/history_of_genetically_modified_organisms.pdfIn PDF document text
- https://f856bbc4-01c8-45e4-8891-a53c5ee59fd0.filesusr.com/ugd/8e827e_20aeb34700364177af30c7d054e872ed.pdf?index=trueIn PDF document text
- http://zijupowisupol.rf.gd/html_form_input_submit_vs_button.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a175483a-0cc9-49fb-aa02-a1e2f8a131f3/98391452159.pdfIn PDF document text
- http://kifarir.rf.gd/sojipa.pdfIn PDF document text
- https://dec4a425-646e-450a-80ca-a73a75d058ad.filesusr.com/ugd/ba3095_c568a341bf6b46e693ff5dacbd4d448e.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010995.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10995 | 5356 bytes |
SHA-256: a8fee0ba9c5e03fad3df73f427d1c693bd25301f8f73d2c14b60c90c3509327e |
|||
font_01_sfnt_off00011bb3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11BB3 | 10468 bytes |
SHA-256: 9d830c7ed8f2f5442e1904e1f62ad2625205b336cbdb1c1105440aa93783302b |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.