Malware Insights
The PDF file contains numerous embedded URLs, many pointing to link farms and potentially malicious domains, as indicated by the 'PDF_SEO_LINK_FARM' and 'ML_NYX_PDF_MALICIOUS' heuristics. ClamAV also detected it as a 'Pdf.Phishing.Trojan'. The document body, though heavily obfuscated, appears to be a lure related to scheduling Uber rides, suggesting a phishing or social engineering pretext. The presence of embedded URLs strongly suggests an attempt to redirect the user to malicious sites, likely for further exploitation or credential harvesting.
Machine Learning
- Nyx PDF Classifier malicious score 0.9916
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://philabc.ru/pbw?utm_term=how+to+schedule+an+uber+with+multiple+stops
- https://jigurojo.weebly.com/uploads/1/3/5/3/135321607/e2da45b.pdf
- https://static.s123-cdn-static.com/uploads/4484375/normal_5ffa2e6d4359f.pdf
- https://xopaluwejur.weebly.com/uploads/1/3/1/8/131857284/3df7cb2f6fe2.pdf
- https://cdn-cms.f-static.net/uploads/4407085/normal_60669c8369404.pdf
- https://joxobupapi.weebly.com/uploads/1/3/1/4/131454586/8686345.pdf
- https://kisuwirabavaruz.weebly.com/uploads/1/3/3/9/133999170/9b4ef650f61d90.pdf
- https://mamunazeve.weebly.com/uploads/1/3/0/8/130814121/2807228.pdf
- https://static.s123-cdn-static.com/uploads/4409421/normal_6009a8b52e8f5.pdf
- https://static.s123-cdn-static.com/uploads/4486745/normal_5fc92bb86ab69.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/682697af-242b-46ec-a9b9-cc0ee52a4751/vonotijaladisu.pdf
- https://uploads.strikinglycdn.com/files/523c43bf-dbe7-49b1-a69e-5e31debb0bd8/fiteniwuwem.pdf
- https://uploads.strikinglycdn.com/files/7b7b9eea-5468-475f-912a-3c73ff6dbdfc/vizio_36_2.1_sound_bar_system_setup.pdf
- https://uploads.strikinglycdn.com/files/500cedd3-d253-40fb-be28-3ae14efc2cc6/what_is_t_mobile_cellspot.pdf
- https://uploads.strikinglycdn.com/files/a570b96c-5db7-41a8-a9e7-d97cf52af432/what_does_igf_1_lr3_do.pdf
- https://uploads.strikinglycdn.com/files/bb08539f-b639-4dd8-bbf1-57a1b19ff09a/72787877244.pdf
- https://uploads.strikinglycdn.com/files/69d151b2-10e0-490e-bb35-2a97cd33343e/89285368498.pdf
- https://uploads.strikinglycdn.com/files/2fa73e86-99db-4c4c-b78f-b6fc5eb1d44a/trigonometric_identities_exercises.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e585.bin1484298350fd940c19e3d1d23df7029cc631d198b450562e6c76b9a26568a77c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE585 | 5504 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.