MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are SEO-optimized to appear as legitimate document downloads. The heuristic PDF_SEO_LINK_FARM indicates a link farm designed to drive traffic to potentially malicious sites. The ML classifier and ClamAV detection strongly suggest malicious intent, likely phishing or malware distribution via these links.
Machine Learning
- Nyx PDF Classifier malicious score 0.9980
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/award?keyword=devi+bhagavatam+pdf+tamil
- http://about-central.com/75313527200lulb7.pdf
- http://changepass.online/ukulele_strumming_patterns_4_4d4fg6.pdf
- http://nanolenka.xyz/what_spider_man_comic_should_i_start_with1dj3d.pdf
- http://deemonatrafik.xyz/60600365684rh3ct.pdf
- https://tivenudonokokom.weebly.com/uploads/1/3/0/9/130969369/4f353162a44549f.pdf
- http://quinzsy-studio.design/hp_laserjet_m1319f_mfp_driver_for_wiz6duj.pdf
- https://cdn.sqhk.co/fajoliteve/9op2jia/82918211103.pdf
- https://jovanifapekiba.weebly.com/uploads/1/3/0/7/130739678/560b3d3e0da17.pdf
- https://cdn.sqhk.co/woravejafeto/chbTgfY/jegos.pdf
- https://furureseseruwa.weebly.com/uploads/1/3/4/4/134481841/bokosifidisi_zekesejiw.pdf
- https://gulijigomun.weebly.com/uploads/1/3/4/3/134350957/6af0ff28.pdf
- https://cdn.sqhk.co/pefevepufi/ihfgjii/water_jet_ski_racing_game_boat_racing_3d.pdf
- https://venozosuvizulul.weebly.com/uploads/1/3/0/8/130814909/metawozugekubu_zenadovikax_kosukijutof.pdf
- http://fedorahosted.org/lohit
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/91b31413-f32c-4a90-8bf5-89090a27251a/how_to_write_in_an_engineering_notebook.pdf
- https://s3.amazonaws.com/bejexe/itv2_plus_1_guide.pdf
- https://uploads.strikinglycdn.com/files/2bad312e-55d8-456d-95ed-7ebf0f6b351d/whats_in_a_chick_fil_a_breakfast_burrito.pdf
- https://uploads.strikinglycdn.com/files/e258c4cb-41d3-4d4c-8b50-9bd4c1bd5c13/21229802087.pdf
- https://uploads.strikinglycdn.com/files/9cf1b648-3586-47ca-bdac-9fe274fe8d6e/bugoxojuget.pdf
- https://uploads.strikinglycdn.com/files/a422139f-8692-4499-8202-a97ec5f1d28e/dokuzudamulaxoxanetu.pdf
- https://uploads.strikinglycdn.com/files/e607d65b-5013-4258-af91-362c381ec138/lifonefavuguxekufalo.pdf
- https://s3.amazonaws.com/kefiperizonofu/tezusevonirosetije.pdf
- https://uploads.strikinglycdn.com/files/76660770-7abc-4ba8-82f5-91d2e0c877c1/will_winds_of_winter_be_released_in_2021.pdf
- https://uploads.strikinglycdn.com/files/83103a49-b38a-45c0-98a9-fa39d9b258c6/fitbit_flex_2_hard_reset.pdf
- https://uploads.strikinglycdn.com/files/b960c349-88e5-483b-b294-1426f87016c3/persepolis_comic_strip.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off000118dd.binabf5bb8d311908c1c6cc6a77d3c7db10b4bf57022b32c078a00e980adab20fd4 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x118DD | 25604 bytes |
font_00_sfnt_off000106a9.binec1ab93ff7e3b9d6c0cf28e753470dd77bdbd7154009c3bbb81f96e4fffde007 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x106A9 | 5380 bytes |
font_02_sfnt_off00014c60.bincc80c12163f556f96cd9a7efb65adbcd22f0420cfd346c3b2a569bbca3a8f67d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14C60 | 11828 bytes |
font_03_sfnt_off000173fc.bin5611cc0ce8762456fbacda30bd755e880b57a9810e753ecd4a9b880ae4ba2aa5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x173FC | 3172 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.