MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which point to potentially malicious domains, as indicated by the PDF_SEO_LINK_FARM heuristic. The ML classifier and ClamAV also flagged this file as malicious, specifically as a phishing trojan. While no scripts were directly extracted, the presence of numerous external links suggests an attempt to redirect users to malicious content or phishing sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9983
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/strik?utm_term=tipos+de+derechos+fundamentales
- https://cdn-cms.f-static.net/uploads/4410678/normal_602c51d5b2a9f.pdf
- http://mezogevap.mypressonline.com/arborescence_site_web_exemple.pdf
- https://cdn.sqhk.co/rakapuvad/ooXCcjh/logo_quiz_answers_level_6_wholesale.pdf
- https://cdn.sqhk.co/bogovureg/giajgjd/starlink_battle_for_atlas_ship_stats.pdf
- https://cdn-cms.f-static.net/uploads/4369783/normal_604b3b0752c29.pdf
- https://static.s123-cdn-static.com/uploads/4403808/normal_5fdea29e30a72.pdf
- https://cdn.sqhk.co/fowoleleda/gfifif2/23214781486.pdf
- https://cdn-cms.f-static.net/uploads/4376379/normal_60146795f148e.pdf
- http://fusekimutoxi.sportsontheweb.net/47387233330.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/e9aa98e4-ceaf-4d61-9764-dd3d2b6b7faa/modern_physics_class_12_in_hindi.pdf
- https://5366dd3f-28a3-4342-b8e5-5bed86455aec.filesusr.com/ugd/a92322_f48bae59932a4836b8eba83fc1de3aaf.pdf?index=true
- https://uploads.strikinglycdn.com/files/7a4d1821-5c83-4186-ba92-5932f681186f/nagixe.pdf
- https://uploads.strikinglycdn.com/files/2fcfd4df-cbab-4c09-82a6-d1550ceb9382/34587104456.pdf
- http://bujijawuta.atwebpages.com/psychological_testing_and_assessment_book.pdf
- https://uploads.strikinglycdn.com/files/c534f9b8-7804-4fab-9b78-10515883f59b/bulorugonituwibu.pdf
- https://uploads.strikinglycdn.com/files/fa51c6c2-1358-42f7-a393-8433d2fff3d3/troy_bilt_lawn_mower_belt_replacement_deck_drive_belt_a94.pdf
- https://5ce19dfa-329f-495d-88d1-e1e7834d9072.filesusr.com/ugd/d902bb_6422e54933d8493eab07c4174a7761a1.pdf?index=true
- https://uploads.strikinglycdn.com/files/551dfd0d-1b25-414e-8e2b-abfb5f59ad75/vodebatisekik.pdf
- https://uploads.strikinglycdn.com/files/a91c15e1-b302-4dcf-a28b-710412b8efca/61316505282.pdf
- https://uploads.strikinglycdn.com/files/096d07e8-8bde-446a-b1d1-03f967d242c9/fizowurujusexonozi.pdf
- https://5c90cfa9-af55-48e2-9430-1f3580382729.filesusr.com/ugd/e2b09b_329992b7ce7b42ccb738de6e772d4c1d.pdf?index=true
- https://d1159ab4-cbf5-42eb-897b-83a5e94cd7da.filesusr.com/ugd/536122_4f6f525526c74f38a008e76704fcd8a9.pdf?index=true
- https://uploads.strikinglycdn.com/files/e2878f27-7c9e-4097-8fcc-6c47f7e6f33d/89682013120.pdf
- https://828c6a01-da61-4814-986a-f72e64f4f334.filesusr.com/ugd/cdfdba_276987779fd843c1a1ece0f12f3b550b.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
- http://scripts.sil.org/OFL
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_005_off00013b00.binc01872fdedaf0125bdc07585f9a6ccfacdb9f888cfcb40d0cc5ea1e5e87c3789 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x13B00 | 18576 bytes |
font_00_sfnt_off0000fa3c.bin1b1955f6bdb890a6088b79a8646f78c78f331293bb7fb5c0f30655f57c04a3ce |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA3C | 5344 bytes |
font_01_sfnt_off00010c31.bin3a37df3de72ec4473d970579e20ce90873368aedf9b38621b3d2ccbda9597b99 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10C31 | 1584 bytes |
font_02_sfnt_off0001144d.binfb88a7609305ae3825a4089850913fdabe2f9070816af4fff25d9ef61ffabea4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1144D | 11852 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.