MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file is identified as malicious by ClamAV and an ML classifier, indicating a high probability of malicious intent. It functions as a link farm, directing users to numerous other PDF documents hosted on various domains, with the primary malicious URL being https://lozipotod.ru/strik. The document body, though heavily corrupted, suggests a lure related to educational content for children, likely to trick users into visiting the malicious links. No scripts were extracted, but the PDF structure itself facilitates the redirection.
Machine Learning
- Nyx PDF Classifier malicious score 0.9983
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/strik?utm_term=verbos+en+ingles+y+espa%25C3%25B1ol+para+ni%25C3%25B1os+pdf PDF link annotation
- https://jafobepajimo.weebly.com/uploads/1/3/4/8/134881918/fikipixi_lixik.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4403540/normal_601fe5a5c588b.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4492253/normal_5ffd1ed0dc1e5.pdfIn PDF document text
- https://kogovuvukadag.weebly.com/uploads/1/3/2/6/132682039/bumedanusona.pdfIn PDF document text
- https://xazepobuzu.weebly.com/uploads/1/3/4/5/134582826/b74e086da58a.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4466680/normal_5fe5520418d10.pdfIn PDF document text
- https://xijukuto.weebly.com/uploads/1/3/4/3/134354051/3838250.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4486534/normal_5ff2c10dec89f.pdfIn PDF document text
- https://tabogivazosepa.weebly.com/uploads/1/3/1/8/131871767/e0d13.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4460954/normal_6007e59b46305.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4451929/normal_6013c185b0ac1.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://dc688580-c0ec-4ade-910b-7abffd870ab4.filesusr.com/ugd/096b61_e1e72ef5b7834f758ff7ba6776282417.pdf?index=trueIn PDF document text
- https://ae26bae5-b1f3-4fb2-a0ba-5d2f2d23988c.filesusr.com/ugd/aec2ea_e0d7e0d4607d40b8a0eb0e83957356f6.pdf?index=trueIn PDF document text
- https://bd42ab16-aebe-4c72-ad16-c2e271b509d0.filesusr.com/ugd/c4ccc4_f9510ba7328b47c7bd3a48c9e80d177a.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/ece67695-6436-4823-b875-246bddcc5fbe/sakutanikelujabezole.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fba94ba7-b7f5-4937-ba37-be0216ad8cfc/87076047028.pdfIn PDF document text
- https://d17f4099-ecc1-42b1-9c73-51521793457c.filesusr.com/ugd/4a2613_ee67a5f6d52b411fba8903ad2c75853c.pdf?index=trueIn PDF document text
- https://d80868e2-5d34-4dda-9345-0396294a35aa.filesusr.com/ugd/f9fac6_3c5e3ab91b6948bbb19cc224e2a385ed.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/785f1594-b0b5-4c14-8feb-354ce365062e/xutanuw.pdfIn PDF document text
- https://da89e6ec-52f9-4c28-8de8-447a2e923c0c.filesusr.com/ugd/5e5b2a_0878ac86e9304f808efa7ff2e4d79363.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/c51b6cb5-9369-4f71-965d-48f858202744/kekulegafabemawerufud.pdfIn PDF document text
- https://e8c82854-2a0b-4c0f-82de-bac600ce06e6.filesusr.com/ugd/d017d5_781d50bd9c064ea58b3168e209824489.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fc65.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC65 | 6708 bytes |
SHA-256: 8d108f7df7c1a004704fcb14e5d459eea0b86c5ee69529f8909b6656b989d6c9 |
|||
font_01_sfnt_off00010d47.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10D47 | 5628 bytes |
SHA-256: b37e9e9adb14ef74b42ec3b4eed8a63d5e73007cd8b6903d473c250486d69386 |
|||
font_02_sfnt_off00012032.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12032 | 2576 bytes |
SHA-256: 77f051408e1cf1e6c76d50f01b4ece578881babe702db3675d05430be3bf0da3 |
|||
font_03_sfnt_off00012b9c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12B9C | 12444 bytes |
SHA-256: e96f15647652d4ae0c716d0c726bc9bc6996d76e40bf09bab2eb52c71d289425 |
|||
font_04_sfnt_off000153d9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x153D9 | 17832 bytes |
SHA-256: f385b5fafd089f994dc59a7b4d05811fb138c9747fb05c5da2046cd51306a340 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.