MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/strik?utm_term=ejemplo+de+comunicacion+entre+dos+personas PDF link annotation
- http://kulotufiw.mypressonline.com/95754810674.pdfIn PDF document text
- http://vijexibat.mywebcommunity.org/44258924584.pdfIn PDF document text
- https://negofajosodin.weebly.com/uploads/1/3/5/3/135314147/rerawavepeval_razufovazoxe.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4466408/normal_5fdc81cfa49b7.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4384468/normal_606d5944bebde.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4420448/normal_6037bc1931a9d.pdfIn PDF document text
- https://zakoponuzu.weebly.com/uploads/1/3/5/9/135992890/xeviropixa_rojano_maral.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4407813/normal_604d0774019c7.pdfIn PDF document text
- http://xabudumame.mypressonline.com/vazuremexikekobibogoka.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4480590/normal_5fe62fa9bf19b.pdfIn PDF document text
- https://deremorukoj.weebly.com/uploads/1/3/4/4/134490203/c07390da.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/8ea39994-6e6e-464d-a77b-5d73d4b9f5e5/all_american_boys_summary.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2cfa9200-dea5-46ed-abf4-259c58c0d0e7/45423832421.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/43ab8fc9-7c10-47f6-8a43-6de62f2770af/leadership_theory_and_practice_northouse_8th_edition.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2e787ff3-4be4-4c66-8431-d5ce06a6e2b1/how_to_connect_vizio_sound_bar_to_samsung_tv.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5bacc829-3eea-4ec2-8d8f-5d4f70eb5f93/69113937933.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/60939b52-1d82-42c7-a479-3db1c5cfe754/fundamentals_of_pathology_2018_free_download.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/076c29cc-79d1-4905-903d-32f2fc0308ae/massachusetts_drivers_license_restriction_codes.pdfIn PDF document text
- https://d86ad34a-7df2-4f47-937b-a12ab5abc0fa.filesusr.com/ugd/8cbfce_d9cd2abecd11434fa52504a35c23d422.pdf?index=trueIn PDF document text
- https://0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com/ugd/8b97dd_b40da32d2f2342c388724118eb84cde2.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/f4716ebc-6378-4ce0-9523-051c4bfeba2e/how_often_do_penny_stocks_make_it.pdfIn PDF document text
- https://fab88ded-2f12-46c9-b6ec-f290036286cc.filesusr.com/ugd/cce69c_237588d30a9248a18675e8ac90b22876.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/7e8b871a-bd12-4e12-b9d5-ac6691668858/udi_rc_drone_u818a-1.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c4926574-67e3-4761-ada0-31a28ed5e770/4175264036.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ef80.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEF80 | 5252 bytes |
SHA-256: 5a701acee9fbfc893001ddcd579eb21fb58f705be7e406fe7ca9b3e94b3e8f0b |
|||
font_01_sfnt_off00010143.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10143 | 12200 bytes |
SHA-256: 415ec9629fa7f045c0fbf6261c6144ce3cbce39d1bf08cd160fd097682110d75 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.