MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, identified as a link farm, with one prominent URL pointing to a 'kitchen tools worksheet' which is likely a lure. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or SEO manipulation. No scripts were extracted, but the PDF structure itself facilitates the redirection.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/wix?keyword=kitchen+tools+worksheet PDF link annotation
- https://cdn-cms.f-static.net/uploads/4403283/normal_604ccbaf2cc72.pdfIn PDF document text
- https://cdn.sqhk.co/wuxofepure/4hh83gg/92164505647.pdfIn PDF document text
- https://cdn.sqhk.co/movumatoz/2sihrjf/gibepekawetexavulisanopa.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4416514/normal_6043ef3ce63c3.pdfIn PDF document text
- http://fruits-summer.fun/43151763690jk9c2.pdfIn PDF document text
- http://startask.ru/creature_of_fenkenstrain_guide_osrsidu6i.pdfIn PDF document text
- https://cdn.sqhk.co/sivojadirabe/PEijhax/asteroids_coming_to_earth_2020.pdfIn PDF document text
- https://cdn.sqhk.co/rinilafexowi/Zhcjbhe/microsoft_teams_for_mac.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://bbaef297-c986-4b42-acb3-0fd65605e280.filesusr.com/ugd/e9fc71_46cff5c0227c40ba8bcf88c9db014f78.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/cf3ae7b1-46f7-4cbc-a6e8-605af167b254/peterbilt_diesel_technician_salary.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1f6a90bf-1cdf-4393-bccc-1e78232b7cf6/tixegizedorunurutakex.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dd70d9e3-5272-49f9-bfb1-004235bcca05/58900896960.pdfIn PDF document text
- https://a765b249-d442-4b07-8ea9-8318d996b894.filesusr.com/ugd/902d29_bf7370012ecf4644853f12824da7087f.pdf?index=trueIn PDF document text
- https://91953a53-6f32-4f2a-9b2e-0f954541ff31.filesusr.com/ugd/dad90e_774d95bd778c43c799267c73cbcc1119.pdf?index=trueIn PDF document text
- https://6346cca1-8be9-442e-91e0-e35201572fa6.filesusr.com/ugd/a8c077_a6520be212364ca59910b18504599b1a.pdf?index=trueIn PDF document text
- https://901c4554-6fda-40bf-8344-1f1538f5dc06.filesusr.com/ugd/a76634_6f0f99a8f2dd4cd2987733381a1bce14.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/deaff4df-f5c1-4640-8ef5-cceea42a6d19/68938381218.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e8da.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE8DA | 4588 bytes |
SHA-256: e430e4e6aa4a093e5b15ed97f1ce820dbff4a1d410b8efd4db8d7cd9dd9d8e19 |
|||
font_01_sfnt_off0000f862.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF862 | 10812 bytes |
SHA-256: d9c9b447aceb56726f0189022ef6c1c18e7b1f50ab7d81ace95b36efffef9ef7 |
|||
font_02_sfnt_off00011d5e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11D5E | 4324 bytes |
SHA-256: d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.