MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
T1059.007 JavaScript
The PDF contains numerous external links, many pointing to other PDF files, suggesting a link farm or redirection mechanism. The 'SE_CLICKFIX' heuristic indicates social engineering to prompt the user to execute commands, a common tactic for downloading and running further malicious content. While no scripts were directly extracted, the PDF structure and heuristics strongly suggest an exploit or downloader.
Machine Learning
- Nyx PDF Classifier malicious score 0.9954
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
ClickFix social engineering attack high SE_CLICKFIXDocument instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/123?utm_term=steam++finished+but+restarted
- https://cdn.sqhk.co/wakewafo/TF4Sqjh/dafubolusamukezenusikise.pdf
- http://trujillostacoshop.com/candy_legends_codeszk8tq.pdf
- https://tojuxumisadef.weebly.com/uploads/1/3/4/7/134714483/mipotes.pdf
- http://myshoes.moscow/93504255187cbgjf.pdf
- https://jinozeposejide.weebly.com/uploads/1/3/1/4/131453810/a1dfc6ae9.pdf
- https://semogabetik.weebly.com/uploads/1/3/1/4/131482882/jupaduwebefilapu.pdf
- http://tryse.xyz/97338022148dkjsn.pdf
- https://cdn.sqhk.co/vemegunir/fqjb14m/new_english_song_2020_with_lyrics.pdf
- https://cdn.sqhk.co/vetelojid/jYBpjd2/sporty_gran_runes.pdf
- http://hayatevesigar.online/68608145828u4qbk.pdf
- https://kevititexozasen.weebly.com/uploads/1/3/2/7/132712545/8a3ca830.pdf
- http://verification-help.com/photo_collage_maker_for_iphone_wallpapervfz4k.pdf
- https://wuwemupijebuvat.weebly.com/uploads/1/3/4/0/134012408/xazudebaxavoxif-kililisavumu-juwomarekedipi.pdf
- https://cdn.sqhk.co/pumevigatare/adiheib/magoxefanobijeniki.pdf
- https://cdn.sqhk.co/dagufiwus/jWWhajb/fastest_launcher_app_android.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/c7ff9ba3-9dec-4722-84fd-ebeda1332492/pelicula_el_mundo_de_sofia_en_espaol_completa.pdf
- https://9907981b-0bc7-4fd3-a434-169f7cdadf42.filesusr.com/ugd/575363_2a8e7327fe984e7f899667988428ae69.pdf?index=true
- https://uploads.strikinglycdn.com/files/6ddbe911-c0ce-4d37-a1b9-fd14d5cb779f/zazodoxixujimepofakoguv.pdf
- https://uploads.strikinglycdn.com/files/703e90f5-f596-4a09-ad40-713c1e9208e8/mechanical_engineer_role_in_manufacturing.pdf
- https://uploads.strikinglycdn.com/files/78ddc34a-1655-4a46-93fe-d32bd09d747d/xunixegelawitipod.pdf
- https://uploads.strikinglycdn.com/files/38ee7317-d231-43af-9248-b6ec7381ff96/gefogakigedezerizofev.pdf
- https://uploads.strikinglycdn.com/files/715389a5-6f1a-45db-bb31-e64a691e4c74/19670203309.pdf
- https://ac3db616-04cb-40f1-8357-c67041f5e20c.filesusr.com/ugd/eda9ba_7c886ffb38ce4c579c92121a2667da5b.pdf?index=true
- https://uploads.strikinglycdn.com/files/8adcd906-9a58-4756-aae6-f9a5f7e8c34a/reif_principles_of_statistical_and_thermal_physics_f.pdf
- https://972af30b-04c2-4618-b911-83ba0b7fef9e.filesusr.com/ugd/84a5c6_d42c13cb6a22405d967c058240417b0c.pdf?index=true
- https://8533cbf3-c0d6-400c-bdf8-8ca38cf0242b.filesusr.com/ugd/135178_6c9874dc7bb446b39dec377655bc3d2e.pdf?index=true
- https://uploads.strikinglycdn.com/files/37ce7595-2806-48fd-b764-cd7f8dae9a4f/advanced_microeconomics_hal_varian.pdf
- https://uploads.strikinglycdn.com/files/db71c593-9b4b-4e7b-b835-27e3e6d36eaa/38146294366.pdf
- https://uploads.strikinglycdn.com/files/83a4367e-9c8b-40c6-bb69-3ad11c516c4b/xarikudag.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fbcb.binda374b78ebd068413c8602e9fb019a3fa42c83de68b7c8d336311c00e05f33a3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFBCB | 5360 bytes |
font_01_sfnt_off00010dd8.bin0f725c869667acc892f48d0d1e5364c803337b3f505abe9c140b64b139971c22 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10DD8 | 11020 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.