MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9958
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/wix?keyword=charlie%2527s+saginaw+mi+menu PDF link annotation
- https://static.s123-cdn-static.com/uploads/4464709/normal_5fec2f9b2e0e0.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4476301/normal_601dad54343f6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4381546/normal_60350068e1c31.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4383561/normal_6064a7cca5bf8.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4499299/normal_606891b3de50a.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4370077/normal_60048601c68e4.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4408343/normal_5fc67c9ea4240.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4402745/normal_5ff4ae733907d.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4501231/normal_5fcf6f3122153.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4403274/normal_60270eeb90a2a.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/befafuni/what_was_one_cause_of_the_second_great_awakening.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b5762f7a-6edb-4480-ba43-49257a6929b8/pukivowapofimelowigutiros.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/efc1a2a6-4877-4c28-9ce0-cf803bf2a031/25589861215.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1441b8da-d8ca-461a-a064-24f7e60a589b/tensile_test_experiment_lab_report.pdfIn PDF document text
- https://s3.amazonaws.com/jopomodilamego/xilevadu.pdfIn PDF document text
- https://s3.amazonaws.com/popilo/gexirox.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0d4c13b2-4c5c-401e-a081-d36f4126ef01/king_kutter_xb_4ft._xb_rotary_tiller.pdfIn PDF document text
- https://ec560393-4650-4708-bf0c-d08fceb8458c.filesusr.com/ugd/ca69db_1fe47b83568f43a28cffc5e79e3c659c.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/5f85fcc0-2d15-43c4-bd10-736bfe4c469f/25997057104.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e53a54bf-b347-450b-b0ad-ea9c559a9234/what_is_a_nfc_reader_writer.pdfIn PDF document text
- https://86a9da1b-0b57-4b35-a77a-523886b904cd.filesusr.com/ugd/0d9a50_694f2c2422294436bed87e76181adafa.pdf?index=trueIn PDF document text
- https://64f1e6a9-4530-4009-9f9b-67b91dd69f79.filesusr.com/ugd/76b6de_cbec83e8b2354a4d95f59063487223c0.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/0a794f30-e473-4732-934f-0a13aaaaaf93/how_to_calculate_real_per_capita_gdp.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/242b9bb8-1176-4a1c-a7e4-4f24f7177cc5/fimarune.pdfIn PDF document text
- https://s3.amazonaws.com/xewamejixolefaj/kumon_math_worksheets_grade_2_free.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9b1b7acc-8a9d-4e78-b4ac-718ac1b472f5/21002507241.pdfIn PDF document text
- https://s3.amazonaws.com/sojenozap/autodock_vina_free_for_windows_7.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010d58.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10D58 | 5132 bytes |
SHA-256: cfd821951c97852721b1bbbe7b7244ae5d4405b4ab16fad2ed649865ffa43d73 |
|||
font_01_sfnt_off00011eb0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11EB0 | 11616 bytes |
SHA-256: 1a006341688d7f70c0fcafe3567011ba3321c931ace3bdbe619386b62b05e6fd |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.