MALICIOUS
174
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file exhibits characteristics of a phishing lure, utilizing an image-based design with a clickable action to redirect users to external URLs. Heuristics indicate a link farm structure, suggesting an attempt to distribute malicious content or engage in SEO manipulation. ClamAV detection confirms its malicious nature, classifying it as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.7228
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LUREPDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 48 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dugedepap.ru/award?keyword=anfotericina+b+complexo+lipidico+pdf
- https://cdn.sqhk.co/didowolikex/iijezie/gusodakalikumuvumuzavat.pdf
- https://cdn.sqhk.co/setawigiz/7hbVmFA/free_images_for_desktop_background.pdf
- https://cdn-cms.f-static.net/uploads/4369524/normal_5fd85bef17160.pdf
- https://cdn.sqhk.co/ninuxoti/gFjhhhg/color_by_number_multiplication_free_halloween.pdf
- https://cdn-cms.f-static.net/uploads/4382208/normal_601cb309bc57e.pdf
- https://cdn-cms.f-static.net/uploads/4481540/normal_606031c7d3c7d.pdf
- https://cdn-cms.f-static.net/uploads/4409096/normal_6056cc291daa5.pdf
- http://bitcoinlearningcentre.online/xoguboramilorigavapu53.pdf
- http://fitit.space/mezuxafovevegudufox2lg9m.pdf
- https://cdn.sqhk.co/livukigelo/hgj6rEh/tugilofomuwasowamebixuw.pdf
- https://static.s123-cdn-static.com/uploads/4447436/normal_5ff047f6c585b.pdf
- https://878ee1be-828d-48b9-a24a-84283cf66a1c.filesusr.com/ugd/86936c_db9ab6c68bbf4e18b4456b0e1e9df953.pdf?index=true
- https://e510c2d5-567e-4a96-89ff-abc18316baf7.filesusr.com/ugd/8a9bcc_c8b88161b4f74fa8b0f3066ec928b7a0.pdf?index=true
- https://6a9ecc2b-05c3-4056-8705-773ae6be8cdd.filesusr.com/ugd/7a359d_7c16550467844e6b854a87ccc897c059.pdf?index=true
- https://98350ace-7ac4-4f38-a9d9-579fdad8050b.filesusr.com/ugd/9b2d9b_c91f08c45ddd4b32b5ae4d778be95f29.pdf?index=true
- https://591379ed-26d0-4405-baa7-5b8dadede013.filesusr.com/ugd/866ffa_a12bd1bba0ba459fa32b9d305d5f2ba9.pdf?index=true
- https://d4cba69e-f3c5-4a64-9e40-69ba24924691.filesusr.com/ugd/b73feb_20e29c0f534142718aa59c30c5dbbc62.pdf?index=true
- https://3e80c8bf-0031-4ca1-bfa9-4484641fefed.filesusr.com/ugd/08103e_7f6b46c7167a42bf998322996c77e963.pdf?index=true
Open this report in the interactive analyzer, or submit your own file for analysis.