MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, many pointing to disposable domains, suggesting a link farm designed to direct users to potentially malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, likely phishing or a trojan delivery mechanism. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a phishing lure, possibly leveraging JavaScript for redirection.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/wix?keyword=aicp+practice+test+questions PDF link annotation
- https://static.s123-cdn-static.com/uploads/4382617/normal_60026f39a2ad2.pdfIn PDF document text
- https://vefaruturibil.weebly.com/uploads/1/3/4/5/134525254/3548689.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4501810/normal_6056c0061b0b7.pdfIn PDF document text
- https://furepaxedipi.weebly.com/uploads/1/3/4/7/134710013/fejupekuzede.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4376612/normal_602d9865b0f92.pdfIn PDF document text
- https://jegetujo.weebly.com/uploads/1/3/5/3/135300600/ruzugijezuxabonufad.pdfIn PDF document text
- https://nimifitirujaga.weebly.com/uploads/1/3/4/6/134693460/61ab04e8.pdfIn PDF document text
- http://vejaginupivedez.iblogger.org/2003_mercruiser_5.0_mpi_fuel_filter_location.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4423431/normal_60280f27c67f6.pdfIn PDF document text
- http://logusiba.22web.org/17388394257.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://f43304fd-85e4-489a-8612-81977e01be4a.filesusr.com/ugd/b6f504_f4409b802d8a4d6ca413142b4eb76d60.pdf?index=trueIn PDF document text
- http://dixadutawuk.epizy.com/how_long_can_you_control_diabetes_with_diet_and_exercise.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/188a58da-0edf-4de5-aa24-a819d9a0f3cd/stuart_hall_representation_and_the_media_summary.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6939f42d-ff60-4cae-b2cc-e3f93c212bc2/colleges_that_offer_electrical_engineering_near_me.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/57c5e1ea-15b8-4288-aeb8-d676f552acc0/xojolotaloxovitez.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9deb74ab-3b5a-4fe0-8b34-8bf0f080fd52/nanekinuzefinovuniv.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bbef4489-9961-40f7-8fcf-aac758c31171/how_to_use_elite_platinum_air_fryer.pdfIn PDF document text
- https://edefa294-c65c-46c5-840b-8a4669b9fdfe.filesusr.com/ugd/e4a001_4f6d848bbf15405fa935867a48bc2324.pdf?index=trueIn PDF document text
- https://d4bcd744-2348-4fe3-9006-05b2fcbd3cbd.filesusr.com/ugd/704566_73e8cb9e7cf84681b8025955c03f138b.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/f6c9f25d-1938-4589-beb0-2b56f9f51a00/60492979340.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/05ea9259-2a08-4548-aa32-58f6fddefae8/does_dish_network_have_4k.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e644.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE644 | 5012 bytes |
SHA-256: 4ee172ee064a9d0d80e3e947de4cd80a1ab30fbb2d230e3c77de5fa1c3e5c3ca |
|||
font_01_sfnt_off0000f763.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF763 | 11256 bytes |
SHA-256: 8391a4d851dc3044f268cec624fd0a00a2b6bbecc45762b32ee78a8ab1772788 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.