MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, with one heuristic specifically identifying a 'PDF_SEO_LINK_FARM'. The primary malicious URL identified is dafemum.ru, which is likely used to host phishing content or further malicious redirects. ClamAV detection as 'Pdf.Phishing.Trojan' further supports a phishing or malicious content delivery intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/wix?keyword=caphras+stone+extraction
- https://nulivuxod.weebly.com/uploads/1/3/0/7/130776854/viximapevez_nabitur.pdf
- https://giridoxaxe.weebly.com/uploads/1/3/4/7/134703098/8f9a8f5709e28c0.pdf
- https://wuwuleli.weebly.com/uploads/1/3/1/3/131398564/566766.pdf
- https://dutosagow.weebly.com/uploads/1/3/0/7/130775111/7995879.pdf
- https://tedajurilazunu.weebly.com/uploads/1/3/0/7/130739962/ribewerutizefog_mexokajejefixen.pdf
- https://ragusixiseditof.weebly.com/uploads/1/3/0/8/130814169/nitako.pdf
- https://cdn.sqhk.co/puxitika/eVpWgeN/wafetimakuvuxibotetata.pdf
- https://sagagokibifaku.weebly.com/uploads/1/3/4/6/134625973/rebajuvox_vetuzogovujuvi_fatofu_meraxeraguwad.pdf
- https://cdn.sqhk.co/nuvexajamu/BgcUbh8/gpisd_skyward_login_garland.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/200b82aa-092a-47e4-a181-2015f34be4b3/dictionary_of_literary_terms_by_martin_gray_free_download.pdf
- https://uploads.strikinglycdn.com/files/61117b69-100b-4073-bd49-07109e14cdbf/5785063623.pdf
- https://uploads.strikinglycdn.com/files/02eb92d2-8abd-4fa3-98da-0ca43b19e4a2/kogepade.pdf
- https://s3.amazonaws.com/labitajaxatufib/how_to_play_the_guitar_beginners.pdf
- https://s3.amazonaws.com/dojonuta/35605453254.pdf
- https://uploads.strikinglycdn.com/files/6d499bf6-aab8-49ac-9708-eb1e3e8837bc/good_healthy_food_to_lose_weight_fast.pdf
- https://s3.amazonaws.com/vifusupegiza/slideshow_powerpoint_template_free.pdf
- https://uploads.strikinglycdn.com/files/63166848-4787-443a-9608-e2d185ae277c/jolasiba.pdf
- https://uploads.strikinglycdn.com/files/edd5b7dc-1a6c-44df-ab28-ea86a870f1f3/how_to_use_hisense_aircon_remote.pdf
- https://uploads.strikinglycdn.com/files/5ce9e6ff-4bdc-4a0c-8e0e-6a7ee20760b6/69243155274.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f873.bin3602c8ec9342ba02e134e907829bfbb311fa391ee1e85cb435e742e943d31f4a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF873 | 3540 bytes |
font_01_sfnt_off0001053c.bind258461abb44ca323bd12be58b732b40fa7528ff8abf010f0577157b129c6a5f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1053C | 4964 bytes |
font_02_sfnt_off00011617.bin84b8667742bc3e41d9eaea50028f0c9d7f53d2cb66d421d3fdf317778fdd2722 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11617 | 11352 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.