MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of external links, identified as a link farm, and is flagged by ClamAV as a phishing trojan. The document body, though heavily obfuscated, suggests a lure related to 'piano sheet pdf'. The primary attack pattern involves directing users to malicious URLs, likely for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/123?utm_term=you+are+god+alone+piano+sheet+pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_60371bea4b957.pdf
- https://xutezanepone.weebly.com/uploads/1/3/3/9/133999331/6134306.pdf
- https://xogepojofaridel.weebly.com/uploads/1/3/2/7/132741214/wominowufubi-barisejiwogufi-nanujemusanowuk.pdf
- https://tagagenefesogi.weebly.com/uploads/1/3/4/8/134864131/29c9b2b799.pdf
- https://fejomuzuzozasas.weebly.com/uploads/1/3/4/7/134748710/tapodenaxef.pdf
- https://xalakadumikimam.weebly.com/uploads/1/3/1/4/131437423/somupabalaj-pedurexaz.pdf
- https://furamakivagoj.weebly.com/uploads/1/3/0/8/130814247/d39b3670f2117.pdf
- https://katubebadidi.weebly.com/uploads/1/3/4/4/134474785/gutevoromiramu_midawezifak.pdf
- https://cdn-cms.f-static.net/uploads/4473947/normal_60581304356cc.pdf
- https://ravuripuzi.weebly.com/uploads/1/3/5/9/135958818/fakowis_zagatemubuwoxek_migaxirasuz.pdf
- https://static.s123-cdn-static.com/uploads/4484805/normal_5ff848d0abe11.pdf
- https://fiwujewi.weebly.com/uploads/1/3/0/9/130969997/mopoz.pdf
- https://jofenunamupil.weebly.com/uploads/1/3/4/3/134343358/sememib.pdf
- https://tujarabevazedi.weebly.com/uploads/1/3/4/2/134235746/lemevevifef.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/aca23faf-ec50-4f6a-8001-4a24d2c57943/35122883029.pdf
- https://uploads.strikinglycdn.com/files/933a06eb-f47a-44a6-b786-9622ed0a8280/wuxobunenerejaruradawomod.pdf
- https://uploads.strikinglycdn.com/files/9a3980f7-d738-41f8-8eba-a36f34ba0219/how_do_i_reset_my_canon_mp250_printer.pdf
- https://uploads.strikinglycdn.com/files/2f99154a-1e69-41b7-9710-5439c427cff5/gogimezitizuzivem.pdf
- https://uploads.strikinglycdn.com/files/d857c46f-0000-449e-9b4f-d1ad5b2935e7/jubolaxepegidavolal.pdf
- https://uploads.strikinglycdn.com/files/90b68ef2-460e-4ad4-9e18-80733ade56f7/modejobefevusikipizaf.pdf
- https://uploads.strikinglycdn.com/files/a7f46a5e-614b-4fc6-a225-1a2cee15e9f4/new_pinoy_movies_2019_free_watch_online.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ea61.bin01b09a88520870f357f00d9e503c999d31e750f7435c3cf160749e142b875f8a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEA61 | 5264 bytes |
font_01_sfnt_off0000fc42.bin4028072dd60bfe6e130ca7e118562b0d2b67c41e2c66eef4c3091ca12c158faa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC42 | 11448 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.