MALICIOUS
132
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains embedded JavaScript and a high number of external URIs, many of which point to potentially malicious domains. The PDF_SEO_DISPOSABLE_LINK_FARM heuristic indicates a link farm strategy, suggesting the document is designed to redirect users to various sites. The embedded JavaScript likely facilitates the redirection or further malicious actions.
Machine Learning
- Nyx PDF Classifier malicious score 0.5541
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://limsurdua.com/contents/files/sifowilu.pdf In PDF document text
- https://www.rath-catering.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613105fc6fe6a---goxoriponezaxefemutewavap.pdfIn PDF document text
- http://garankuccu.com/upload/fckimagesfile/a024ae81a1e6704dae83f9a51efca8c1.pdfIn PDF document text
- http://www.clc-engineering.com/siteuploads/editorimg/file/86433429458.pdfIn PDF document text
- http://bige.vn/uploads/userfiles/file/18707339966.pdfIn PDF document text
- https://deesudcoolingtower.com/userfiles/file/46245408110.pdfIn PDF document text
- http://slabowidzacy.smprzemysl.pl/ckfinder/userfiles/files/ginevamen.pdfIn PDF document text
- http://ttmplus.com/userfiles/files/47277932785.pdfIn PDF document text
- https://birgatour.mn/js/ckfinder/userfiles/files/83900997569.pdfIn PDF document text
- https://www.auto-ecole-rive-droite.fr/ckfinder/userfiles/files/tibemeporolekedij.pdfIn PDF document text
- http://arci-mp.fr/admin/File/58270942629.pdfIn PDF document text
- http://zaragozalawoffice.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/76395804023.pdfIn PDF document text
- https://98ing.com/upload/ck/files/20210910_181751.pdfIn PDF document text
- http://domario.ru/userfiles/file/88326531543.pdfIn PDF document text
- https://asiarsolutions.com/userfiles/file/sebasejerubikezoduviziwum.pdfIn PDF document text
- http://elfobchod.cz/foto/Image/file/wenisajobu.pdfIn PDF document text
- http://knipia.com/userfiles/file/79694593048.pdfIn PDF document text
- http://www.finanzanlagen-honorarberatung.de/wp-content/plugins/formcraft/file-upload/server/content/files/161371ba1d5d6d---96409419864.pdfIn PDF document text
- http://chizclean.ru/files/fck/file/bobobedewaripaxugewenoko.pdfIn PDF document text
- http://materialdeestudo.top/userfiles/files/zosuwowazuxusemiponuf.pdfIn PDF document text
- http://cermak-expo.cz/data/files/file/jimulejo.pdfIn PDF document text
- http://xn--54-dlcdkamdj4btild5b.xn--p1ai/ckfinder/userfiles/files/56419353166.pdfIn PDF document text
- https://ip-kamera-rendszer.nuttydog.hu/ckfinder/userfiles/files/lufonagokobig.pdfIn PDF document text
- http://zpb-maciejewski.pl/upload/fck/file/36996507091.pdfIn PDF document text
- http://ediljolli.com/userfiles/files/mumisas.pdfIn PDF document text
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=print+to+pdf+windows+10+free+downloadPDF link annotation
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000bffd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBFFD | 16448 bytes |
SHA-256: 50f746e4428622962813ac463698a9967733f9a5bc5f723d5fe760581bb80005 |
|||
font_01_sfnt_off0000ea3e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEA3E | 10752 bytes |
SHA-256: 1fe96aba48771bf17a003c6fac1855d30d43f25454e9031d7f7d28d4c9ba0a4a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.