MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, with one prominent URL pointing to 'zajinet.ru', suggesting a link farm or phishing attempt. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, and 'SE_PASSWORD_ARCHIVE_LURE' suggests the document may be a precursor to delivering an encrypted payload. ClamAV also detected this as 'Pdf.Phishing.Trojan'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9957
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=onkyo+tx+sr705+factory+reset
- https://cdn-cms.f-static.net/uploads/4446273/normal_604499574ed28.pdf
- https://cdn-cms.f-static.net/uploads/4489264/normal_5fe7bce6e49fa.pdf
- https://gibodogud.weebly.com/uploads/1/3/5/9/135994226/3382272.pdf
- https://static.s123-cdn-static.com/uploads/4402720/normal_5ff8b61d64b78.pdf
- https://pimowaxe.weebly.com/uploads/1/3/5/3/135397576/gebaresubekuke_bisutosulav_tobidiwalelawo_tekigukizu.pdf
- https://cdn-cms.f-static.net/uploads/4385216/normal_602da4abf3423.pdf
- https://cdn-cms.f-static.net/uploads/4376358/normal_6026fd7714e41.pdf
- https://static.s123-cdn-static.com/uploads/4408871/normal_5ff1e7d90851c.pdf
- https://static.s123-cdn-static.com/uploads/4471252/normal_5fe54f2fc6183.pdf
- https://cdn-cms.f-static.net/uploads/4444853/normal_5fd107993e39a.pdf
- https://xabonawof.weebly.com/uploads/1/3/5/9/135965837/wuwabexibuviri_zajuri.pdf
- https://cdn-cms.f-static.net/uploads/4374022/normal_601db654e5393.pdf
- https://static.s123-cdn-static.com/uploads/4496818/normal_5ff9ba5912950.pdf
- https://fobewesepujub.weebly.com/uploads/1/3/2/3/132303403/1135680.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/babuxufarizuxur/apple_magic_mouse_2_space_grey_sale.pdf
- https://s3.amazonaws.com/nuxomigo/zejiziriraputixu.pdf
- https://4cd5a77a-be8d-44ba-8952-4177873115c4.filesusr.com/ugd/930050_eb1f206eb28f4ff1ae39e5243f913511.pdf?index=true
- https://s3.amazonaws.com/kiguteperilodu/somawufofegugafosujobora.pdf
- https://s3.amazonaws.com/wiwamoxamo/20602409362.pdf
- https://s3.amazonaws.com/bugutaj/gcc_compiler_optimization_report.pdf
- https://s3.amazonaws.com/wolawatin/ruxosilobevi.pdf
- https://3e1af3dc-cf37-4f58-935d-0a6065bc5ce9.filesusr.com/ugd/3ca236_782319dfcced4f4ea1fda744c718414b.pdf?index=true
- https://s3.amazonaws.com/divexikav/multiplication_worksheets_with_answers.pdf
- https://s3.amazonaws.com/fedufiporara/aadhar_card_correction_form_filling_example.pdf
- https://s3.amazonaws.com/nevovumowa/crock_pot_smart_pot_instructions.pdf
- https://26c1613e-5d28-4fa3-89cb-3d2c9ab59faf.filesusr.com/ugd/fe83c3_a7ab46a322264193861ee89cff098a7d.pdf?index=true
- https://s3.amazonaws.com/pubopelej/searching_movie_parents_guide.pdf
- https://45b0b119-5f8c-43e7-b437-4e12d17c1c81.filesusr.com/ugd/3826db_08e6756e369b45dc89268015ca55e631.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010bc1.binc88b3f3ee5a67cda3098fe60cf64b00fdba5762f5f1b77f35f8bb1fbbacce660 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10BC1 | 5448 bytes |
font_01_sfnt_off00011e79.bined6e5b417eaf3a576f1c1bbe58356ca66bdf2a0f5d7d6509c78aa31303777460 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11E79 | 11228 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.