MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, many of which are part of a link farm designed for SEO manipulation. One prominent URL, https://lozipotod.ru/wix?keyword=learn+to+fly+unblocked+2, is directly embedded and likely serves as the primary lure. The ClamAV detection and ML classifier strongly indicate malicious intent, classifying it as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/wix?keyword=learn+to+fly+unblocked+2
- https://cdn-cms.f-static.net/uploads/4458621/normal_6045ff575bfab.pdf
- https://cdn-cms.f-static.net/uploads/4373522/normal_60510bd905d09.pdf
- https://cdn.sqhk.co/firataxoworo/jx1rs1k/22278941619.pdf
- https://static.s123-cdn-static.com/uploads/4452626/normal_5ffe20542db05.pdf
- https://cdn.sqhk.co/tifobebe/a1Vxia4/56062625768.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://bisapejavi.epizy.com/kosor.pdf
- https://uploads.strikinglycdn.com/files/5c77bc17-5f9e-4dd0-8caf-bcbe8d990733/75505367589.pdf
- http://jigiwema.epizy.com/pdf_market_leader_business_english_course_book.pdf
- https://uploads.strikinglycdn.com/files/306defd3-4696-402d-a969-4b3d0efc7fe0/panchatantra_short_stories_in_hindi_with_moral.pdf
- http://jodetiwozefiso.epizy.com/how_do_i_reset_a_kenmore_elite_dishwasher.pdf
- https://uploads.strikinglycdn.com/files/8f2776c2-97ec-40d4-9a27-8d8d7a548353/yamaha_rx_a730.pdf
- https://uploads.strikinglycdn.com/files/d4125d47-3515-49a4-a100-45c12ae32c48/bedejeru.pdf
- https://uploads.strikinglycdn.com/files/f6a491e8-0991-46ed-840c-cc983bb26548/how_to_put_money_order_on_prepaid_card.pdf
- https://uploads.strikinglycdn.com/files/e632de5d-7058-470d-a146-775ebddc6952/20889825412.pdf
- http://kutegabirena.epizy.com/zeponusenitirikufatasaxa.pdf
- https://4328a374-8b5c-4134-9cef-e132ca5fc89d.filesusr.com/ugd/6732b1_b48f8b18c6b24124a704e85eb0a4b05d.pdf?index=true
- https://uploads.strikinglycdn.com/files/9f39f5b3-85f8-4294-bb42-3c0716458cec/can_you_keep_a_secret_movie_2019_release_date.pdf
- https://a0d2adcf-75bd-42a9-a42a-c23e1c6e9e1a.filesusr.com/ugd/85c99c_1f737613b5024bb5a0bdf81932ef63a7.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dcdc.bin33aef41dd2c6747474120fcbae0ddc8043125cdf05ae82dea2148d5abc2c8e7d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDCDC | 5216 bytes |
font_01_sfnt_off0000eeba.bin40af25f59fb67188d69004bb08e698a70a02948d72eda6d067523f9ce68025f6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEEBA | 10516 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.