MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are disguised as book downloads, indicating a link farm or phishing attempt. The ClamAV detection and ML classifier strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external URIs point towards a malicious document designed to redirect users to potentially harmful sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/award?keyword=atomic+habits+book+download+pdf
- http://guzexesuge.mypressonline.com/25011377223.pdf
- http://lady-bug.club/los_hermanos_karamazov_libro_completoux83x.pdf
- http://pajodumu.22web.org/todo_minimalismo.pdf
- https://visimekariluvog.weebly.com/uploads/1/3/1/4/131483525/9160720.pdf
- http://nadahul.ru/august_2019_sat_answersdfnq7.pdf
- http://gulivopaduro.22web.org/atmospheric_science_an_introductory_survey_solutions_manual.pdf
- http://septiki-rf.website/banenasujwkzpr.pdf
- https://poxomovuru.weebly.com/uploads/1/3/1/3/131381772/jekoxisi.pdf
- http://static-start.top/much_ado_about_nothing_quotes_about_honork5727.pdf
- http://hurricane1.space/pufak1qvkd.pdf
- https://solujasamaro.weebly.com/uploads/1/3/4/6/134695729/kavemamuwagi_patupidike_jemiwux.pdf
- http://naturwows.space/how_did_eleanor_and_park_endyxkw5.pdf
- http://3gusevshop.space/kindergarten_drawing_worksheetsx7tz8.pdf
- https://napokepuwaju.weebly.com/uploads/1/3/1/1/131164128/6a341a6.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://sajekitix.rf.gd/google_calendar_template_2019.pdf
- https://9c33b4df-6f14-41ad-9e94-a3a23f7ed20d.filesusr.com/ugd/2a975f_7d067f78e920437c9b629fe4b9066c8c.pdf?index=true
- http://viniwowosur.onlinewebshop.net/bankersadda_english.pdf
- https://a519209a-2b0a-481f-9fe9-460c873bdc80.filesusr.com/ugd/270e53_376df306abb942969e8766b97c4438af.pdf?index=true
- https://4779f2f8-a33e-4327-9c78-21ee0bcf4620.filesusr.com/ugd/31bf02_07872eb1b9b04b7495ec9b612732c48e.pdf?index=true
- https://08c3cc13-1ce0-4add-927e-a3aed263473e.filesusr.com/ugd/ccf397_dabc25e7d02940d68102e254cceb8b3d.pdf?index=true
- http://podixevobelataw.rf.gd/type_of_antennae_of_butterfly.pdf
- https://0fecb50d-c8db-4b5c-a67e-01a13b1c0e9a.filesusr.com/ugd/da7c2d_ace4fab66c904f57a152c5cdc97f0a74.pdf?index=true
- http://majilutiwuxas.rf.gd/21733657770.pdf
- http://bavatesivo.myartsonline.com/34679751270.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00019563.bin9e0d5e9c9f1ddd1bf6a812cd099a25cc8ec77312bfc5b44f05fd7339d7133789 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19563 | 5584 bytes |
font_01_sfnt_off0001a84c.bince6e58c83ed1f588848d05f922f5f15fa19f25cd43fbbd8fbe0382166839907a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A84C | 11708 bytes |
font_02_sfnt_off0001d028.bin60f53b17f7925ac1818ac9336ea58fd206fea48872b5377b70e6fb8114080afd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D028 | 16132 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.