MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The PDF file was identified as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains a large number of external links, many pointing to disposable hosting, suggesting a link farm or distribution mechanism. While the document body contains garbled text and a reference to 'increase render distance in minecraft realms', the primary malicious activity appears to be the mass distribution of links to potentially malicious or SEO-abusing content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9989
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cdn.sqhk.co/pirasemofoge/6gg5gjg/5398670589.pdf In PDF document text
- https://cdn.sqhk.co/vuwipabobatu/aYehdIz/27952599190.pdfIn PDF document text
- https://cdn.sqhk.co/xejadukoxeta/aLtLhai/swift_vdi_rear_shocker_price.pdfIn PDF document text
- https://cdn.sqhk.co/wapogade/3Ggcghu/71129176696.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://feedproxy.google.com/~r/wb/ENAH/~3/dN4lCoxrs6M/wb?keyword=can%20you%20increase%20render%20distance%20in%20minecraft%20realmsPDF link annotation
- https://ac911ccd-a574-46a9-bbb3-57bb927ff796.filesusr.com/ugd/2735c9_07df883c22274b8494ba42bd452a08d4.pdf?index=trueIn PDF document text
- https://69c5641f-197a-42c1-bef1-daa502c1f1d7.filesusr.com/ugd/948cea_4384d916f46840529a19ba5175a776b7.pdf?index=trueIn PDF document text
- https://f19d2187-ce67-4d04-8798-eef694565169.filesusr.com/ugd/bd4746_1a94dc868c484224a6694b72ced4e299.pdf?index=trueIn PDF document text
- https://b23183eb-b2e5-455e-bc25-91fac1efd10f.filesusr.com/ugd/cc14e4_abfc71225d2641e8a6548177ff1e8a16.pdf?index=trueIn PDF document text
- http://gagisejokunego.rf.gd/xodekujovubuzatugizivi.pdfIn PDF document text
- https://6f84c080-6bd2-4154-8ce1-0e390380bda5.filesusr.com/ugd/defdb4_0b1ea75eb479461e908568f5e3424c36.pdf?index=trueIn PDF document text
- http://rixumigeva.epizy.com/84202038510.pdfIn PDF document text
- http://xugedev.epizy.com/huskee_rear_tine_tiller_6hp.pdfIn PDF document text
- https://c8070bf9-ed42-4c5d-8eb8-ca35ee70f136.filesusr.com/ugd/d38238_1f5d46e41f6a47449daa1c1f742e65a9.pdf?index=trueIn PDF document text
- https://5f1c1209-45f6-45c0-988a-e0aaa04be055.filesusr.com/ugd/ba5820_84e26d936ce24a21b226e21e8ab7a0b8.pdf?index=trueIn PDF document text
- https://cff07a16-13b2-455b-8a78-148a75b158b4.filesusr.com/ugd/cda0c7_667b9ef10a9742958a593f3800b75ea1.pdf?index=trueIn PDF document text
- https://d6ac5066-27fc-4e71-a07d-b30af50dfe8b.filesusr.com/ugd/934fc3_f496499149de42dabd9993463b117c24.pdf?index=trueIn PDF document text
- https://0f4267a5-27df-427f-b7ff-de3c6d4a4cd0.filesusr.com/ugd/9e4921_b00ebf0db9a4485ca0ed8f9473e1ecf5.pdf?index=trueIn PDF document text
- https://9d50af6f-dbf7-41ba-b854-83985329a12b.filesusr.com/ugd/33c377_5aa06f2c73fc4af39e4eea500304e143.pdf?index=trueIn PDF document text
- https://c5e26362-acc3-4c40-9db4-ce0cbd355080.filesusr.com/ugd/681527_870fdecaac5448d285c7b8067cf56a8e.pdf?index=trueIn PDF document text
- https://ff0b3df2-dc61-4aeb-9024-93fa9b5bc175.filesusr.com/ugd/aa14a9_63603f99aff44f6eb4e88c08e50b68fc.pdf?index=trueIn PDF document text
- https://47e244ab-6b1f-4ae7-97e8-86de5b619f9f.filesusr.com/ugd/e1d12c_153a3d06076b41c4b74072b7d79838d1.pdf?index=trueIn PDF document text
- https://c01188fd-d8af-4b86-846b-090f7ecd58d8.filesusr.com/ugd/9058e5_0d40315c8cb14b3dbe3c2e12bb93d86d.pdf?index=trueIn PDF document text
- https://a3c35cc3-4a3f-4d41-ab51-8b3e4b114d30.filesusr.com/ugd/2b25b5_a1b935cfa32e46c0b1cb8b1b23c853db.pdf?index=trueIn PDF document text
- https://9a4b5e96-23fe-4021-9525-787506808755.filesusr.com/ugd/b3318b_c6342871571446aa8d70be7e17adc0b5.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00018979.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18979 | 5176 bytes |
SHA-256: c7d2673471ce555ae242f581673565692a5142ad4678af3f87074928154434c0 |
|||
font_01_sfnt_off00019afc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19AFC | 2896 bytes |
SHA-256: 1206e2151427629aa8ed953110c8c6ff4d89d552397d30be7b238d79d192cf6a |
|||
font_02_sfnt_off0001a72b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A72B | 12812 bytes |
SHA-256: c5d0cae37d2cae10fbe192fbd5c4b39365fdc7044ac1cb7975aa41f32ed8cf6e |
|||
font_03_sfnt_off0001d32a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D32A | 16136 bytes |
SHA-256: e9d46ca126c9f368b2eb088d92f63313cbfc314c96ec0524c1c1495e2757aab3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.