MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by a machine learning classifier and ClamAV as malicious, specifically as a phishing trojan. It contains numerous external links, with a heuristic identifying it as a 'PDF_SEO_LINK_FARM', suggesting an attempt to direct users to potentially harmful websites. The document body, though heavily obfuscated, contains references to URLs that are likely part of this link farm.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/wix?keyword=red+newt+cellars+blue+newt+white
- https://cdn.sqhk.co/sunomedude/jhPidHz/ivry_sur_seine_paris_metro.pdf
- https://cdn.sqhk.co/serodozire/lphdD1s/19747017823.pdf
- https://cdn.sqhk.co/damapegapi/fhghcIy/nibenopuregoris.pdf
- https://xizuxikeg.weebly.com/uploads/1/3/0/7/130740292/bepadoput-simexubu.pdf
- https://vupebuxotilejo.weebly.com/uploads/1/3/0/8/130814562/vekuraw.pdf
- https://cdn.sqhk.co/navififoro/iibgigi/is_dryer_sheets_poisonous_for_dogs.pdf
- https://xedaliwim.weebly.com/uploads/1/3/1/4/131454603/4783.pdf
- https://cdn.sqhk.co/moxinivo/jbie1kU/tafaboruvebiki.pdf
- https://likudone.weebly.com/uploads/1/3/4/6/134681098/jumabuwuxisevajuz.pdf
- https://gutinevar.weebly.com/uploads/1/3/4/6/134611255/rudatazotogab_fixobigun_zavidup_xulerasufibo.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/f4d25e35-c359-4617-b9ef-b5b6a16b7aef/luwavavodazidezubas.pdf
- https://uploads.strikinglycdn.com/files/df743d0b-c0f2-4135-b400-c024d2923ab6/crochet_patterns_for_hat_and_scarf_sets.pdf
- https://s3.amazonaws.com/jinabom/3704488630.pdf
- https://s3.amazonaws.com/lopeteb/67825744560.pdf
- https://s3.amazonaws.com/xajowu/baby_girl_names_starting_with_b_english.pdf
- https://s3.amazonaws.com/muxegeza/vawakodijibibevexise.pdf
- https://s3.amazonaws.com/lodazojamuva/35805759677.pdf
- https://s3.amazonaws.com/sinadi/babuzuwagarazataxarubo.pdf
- https://s3.amazonaws.com/zesotat/72187154202.pdf
- https://uploads.strikinglycdn.com/files/5a22e32a-18fe-4065-b85e-ec1d68f30a97/19703701875.pdf
- https://uploads.strikinglycdn.com/files/a6efcc41-a90c-4b26-bb5e-364738aefd78/genetics_a_conceptual_approach_5th_edition_ebook.pdf
- https://s3.amazonaws.com/nuxulikiwab/neet_2019_answer_key_aakash_q5.pdf
- https://uploads.strikinglycdn.com/files/3df0617f-8912-4bae-bb7a-f138f15de20d/sojubuzezinuvizenu.pdf
- https://s3.amazonaws.com/mujevubutukoxu/voting_ballot_template_michigan.pdf
- https://uploads.strikinglycdn.com/files/dd2e92ca-bfd0-44a6-82f0-e8e5eb8285e3/26220228678.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d56a.binbe3698cd0a823829ae701c4318d46354de99a9acddf110b045656a874ce84b67 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD56A | 5264 bytes |
font_01_sfnt_off0000e75c.bincd8efdc60cdc87c6c0139026a20283511f871b604689408fbd757a96fc183f6a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE75C | 10992 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.