MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a large number of external links, many pointing to disposable hosting, suggesting a link farm designed to redirect users to potentially harmful content. The embedded document body, though corrupted, hints at a lure related to legal documents.
Machine Learning
- Nyx PDF Classifier malicious score 0.9964
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gimoguvi.ru/strik?utm_term=commentaire+d%2527arret+corrig%25C3%25A9+droit+des+obligations+pdf PDF link annotation
- https://wavarojejepifog.weebly.com/uploads/1/3/4/5/134590929/1974188.pdfIn PDF document text
- https://gemiwanot.weebly.com/uploads/1/3/4/4/134495393/logunose.pdfIn PDF document text
- https://leburivirabilaz.weebly.com/uploads/1/3/1/4/131453170/gebevakedejun.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4455684/normal_5ffd805e384fc.pdfIn PDF document text
- https://sabitafev.weebly.com/uploads/1/3/4/3/134308069/2688689.pdfIn PDF document text
- https://mizugoveram.weebly.com/uploads/1/3/3/9/133986338/2755515.pdfIn PDF document text
- https://dibovasejul.weebly.com/uploads/1/3/1/0/131070518/binadidoba_nopezerezupolon.pdfIn PDF document text
- https://tujowijide.weebly.com/uploads/1/3/0/9/130969571/921950.pdfIn PDF document text
- https://degufulu.weebly.com/uploads/1/3/1/3/131379990/7162522.pdfIn PDF document text
- https://vatewiwep.weebly.com/uploads/1/3/4/4/134482367/zubedarupomolab_porip_xuzunu_kapedapaki.pdfIn PDF document text
- https://fofebaxokawapo.weebly.com/uploads/1/3/7/4/137499404/95065.pdfIn PDF document text
- https://zojobowexiwe.weebly.com/uploads/1/3/1/3/131380894/5588305.pdfIn PDF document text
- https://kuvitarige.weebly.com/uploads/1/3/4/0/134095916/pigomosugopawizu.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4497638/normal_6061be0549f4f.pdfIn PDF document text
- https://zulozuger.weebly.com/uploads/1/3/5/3/135310252/74ff072b.pdfIn PDF document text
- https://gakulenem.weebly.com/uploads/1/3/1/4/131437742/lilawukusuzor.pdfIn PDF document text
- https://jubiporosevuzu.weebly.com/uploads/1/3/2/6/132695682/ca6dd1edf.pdfIn PDF document text
- https://mivojunap.weebly.com/uploads/1/3/4/7/134720575/segigeji.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4454821/normal_602ef51d2d888.pdfIn PDF document text
- https://warenumew.weebly.com/uploads/1/3/4/8/134871813/566d515f516e5.pdfIn PDF document text
- https://pusasosabuni.weebly.com/uploads/1/3/4/6/134654602/363208fa09d8.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4413126/normal_5fe5487400b45.pdfIn PDF document text
- https://fedofiri.weebly.com/uploads/1/3/2/6/132681193/3837661.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/16d0a1d7-d52a-4966-a1a6-b58dc0bf3336/tadojubarejufixuf.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2a02d026-4176-409a-a9fc-aa139f3f12c5/53379715927.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5ef2c4dd-77fb-4109-a513-d4ce2d3180f7/my_side_of_the_mountain_movie_book.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/348cf86d-fee8-406d-acc8-af3e2b8f044d/77284253334.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9c96a1e5-82e1-4388-a3c1-12d161c1c9d0/learning_styles_inventory_for_high_school_students.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001072e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1072E | 5696 bytes |
SHA-256: 528b8b886e896b375a108e748e08054a21e86ddd4756f95b182177333d1cffd2 |
|||
font_01_sfnt_off00011a30.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11A30 | 11900 bytes |
SHA-256: 763b8600a00c8c85da4e7ce9bda2588c4965abb187d275c52f28a684a847b123 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.