MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
This PDF file exhibits characteristics of a phishing or financial fraud lure, as indicated by the 'SE_PAYMENT_REDIRECT_LURE' heuristic and the presence of numerous external links. The primary malicious URL identified is 'https://zajinet.ru/strik?utm_term=how+to+draw+up+a+divorce+agreement', which likely leads to a malicious payload or phishing page. The PDF also contains a large number of links to other PDFs, suggesting a link farm or redirection mechanism, and is flagged by ML classifiers and ClamAV as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LUREDocument describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=how+to+draw+up+a+divorce+agreement PDF link annotation
- https://wozukaziximuru.weebly.com/uploads/1/3/4/5/134587045/5319713.pdfIn PDF document text
- https://bufuxilanu.weebly.com/uploads/1/3/4/4/134402831/liwanuwekizap-lotimubis-lujabedatufe-tubezizuzegak.pdfIn PDF document text
- https://xugojegisonixen.weebly.com/uploads/1/3/4/6/134684264/407ed2dd.pdfIn PDF document text
- https://kimiligemapi.weebly.com/uploads/1/3/4/3/134343210/e8f81.pdfIn PDF document text
- https://wasizizinawuj.weebly.com/uploads/1/3/6/0/136096362/pikekaguxu-jitemefuno-wugodowof-rawebofuvo.pdfIn PDF document text
- https://xavexipaw.weebly.com/uploads/1/3/1/6/131636683/xinati.pdfIn PDF document text
- https://ziposubiv.weebly.com/uploads/1/3/0/9/130969570/2210968.pdfIn PDF document text
- https://pesenulowujef.weebly.com/uploads/1/3/5/3/135325158/bajizanowis.pdfIn PDF document text
- https://wisatevifo.weebly.com/uploads/1/3/0/7/130775851/5972771.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/dejolavubukugeb/8795343821.pdfIn PDF document text
- https://s3.amazonaws.com/pubopelej/48086272309.pdfIn PDF document text
- https://s3.amazonaws.com/legenapi/84521912667.pdfIn PDF document text
- https://s3.amazonaws.com/sajatesawodiji/66006535956.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ccf21825-491f-419f-b838-100739161fc6/zebra_zt420_printhead_test.pdfIn PDF document text
- https://s3.amazonaws.com/pukaridimupo/towesepufumosotokaweziviw.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a0ee7bab-8b6c-4f35-a811-972e128886b1/39937597573.pdfIn PDF document text
- https://s3.amazonaws.com/retobifulipo/conversin_de_pulgadas_a_milimetros.pdfIn PDF document text
- https://s3.amazonaws.com/vufuzewasi/don_t_speak_her_name_piano_sheet.pdfIn PDF document text
- https://s3.amazonaws.com/xujitezu/namilevudolazabupuwuxarem.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e139.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE139 | 5296 bytes |
SHA-256: 42abc2a907f0a6b2b89dd1911dc047a14a3ef868a2fbaf071d800c7d79fe67a7 |
|||
font_01_sfnt_off0000f33e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF33E | 11620 bytes |
SHA-256: 64fe1f493a5d1aac40c6f7579f1d794fec683b0ae158e583a85e94f31cde5e0d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.