MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various PDF files hosted on external domains. One of the primary external URIs, https://pelibifir.ru/wb?keyword=armitron%20pro%20sport%20watch%20wr330ft, suggests a potential phishing lure related to product searches. The ClamAV detection and ML classifier further indicate malicious intent, likely related to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/wb?keyword=armitron%20pro%20sport%20watch%20wr330ft PDF link annotation
- https://cdn-cms.f-static.net/uploads/4377407/normal_6015bc2fdfd85.pdfIn PDF document text
- https://kedigijolaga.weebly.com/uploads/1/3/4/3/134331451/xojegebupuro.pdfIn PDF document text
- https://folejate.weebly.com/uploads/1/3/4/9/134902611/7883903.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4451955/normal_5fc84958e69aa.pdfIn PDF document text
- https://vazaratel.weebly.com/uploads/1/3/4/0/134017227/nisigom-siragamoziwodi.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4480898/normal_5fcd25759ecea.pdfIn PDF document text
- https://gekafokolasiga.weebly.com/uploads/1/3/1/3/131384301/7c5067e376577.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4409623/normal_5fe2dd16c3c4c.pdfIn PDF document text
- http://rubka.space/how_to_open_a_sentry_safe_lock_box_without_keyvvgx9.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4415322/normal_6008c14d3edf7.pdfIn PDF document text
- http://segway-wheelchair.ru/8295727795qaf3w.pdfIn PDF document text
- http://uspehdnyaaxyz.xyz/tanederefovodudojcl.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- http://sirovorisolilu.rf.gd/pekaroxamebemupali.pdfIn PDF document text
- http://zumojuluru.epizy.com/how_to_ask_for_a_5_star_google_review.pdfIn PDF document text
- https://c3373aeb-ed74-4f2d-b631-fa679e0a3f6f.filesusr.com/ugd/cbe7f7_23b8a881133643c3897ee5b07acce9ae.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/e5377f4e-8a73-4a21-87da-2d20be6475eb/how_to_use_self_clean_oven_ge_profile.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a3cb3634-70f5-4c26-a9b8-2da37ba37d11/what_is_the_best_weather_station_for_home_use.pdfIn PDF document text
- https://7d6e376e-1ee3-4df5-88c1-8d1511d419f8.filesusr.com/ugd/7dd30d_98a50d848d7a462190f54058984824c6.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f37f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF37F | 5280 bytes |
SHA-256: c9949be2fa174d5ea4e4bf3e3e992a581433a2af22a015a25a972974e7a7b04f |
|||
font_01_sfnt_off0001053b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1053B | 10828 bytes |
SHA-256: 5886ba38dfaa5ec36afedeefe0aefd123c3593631f138dd6cb0dca5487a8dcef |
|||
font_02_sfnt_off00012a2e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12A2E | 4324 bytes |
SHA-256: ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.