MALICIOUS
254
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains multiple heuristics indicating malicious redirection and link farming, including a critical finding for a malicious redirector link. The embedded content, though heavily obfuscated, appears to be a lure related to a 'Panasonic phone' to encourage link clicks. The ML classifier and ClamAV detection strongly support a malicious classification, likely for phishing or to serve a second-stage payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://yafferge.ru/strik?utm_term=how+to+turn+on+the+ringer+on+a+panasonic+phone In PDF document text
- https://forabuluzasojar.weebly.com/uploads/1/3/5/3/135303956/53d46fd251a0736.pdfIn PDF document text
- https://dagaroxir.weebly.com/uploads/1/3/5/9/135973008/jemidomofipupe.pdfIn PDF document text
- https://jilarikogezinuv.weebly.com/uploads/1/3/0/9/130969280/5163431.pdfIn PDF document text
- https://tewuwixo.weebly.com/uploads/1/3/4/6/134629191/b04e80407678.pdfIn PDF document text
- https://gomafaned.weebly.com/uploads/1/3/5/2/135296522/9b817b8e1.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/7e4cc99d-10db-48b7-a39b-9880571d4240/what_is_the_self_fulfilling_prophecy_in_sociology.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/20487f09-3135-4d29-b5c0-382788d313ea/armstrong_ultra_sx_90_furnace_will_not_ignite.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b41fee4a-ede4-4999-8756-712c7d12e8c2/putuj.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0569f723-e33f-4b74-8243-118b195ebd13/what_is_wisp_repeater_mode.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/234a9f34-7fbf-48ad-bcad-5156e01c180e/the_meaning_of_marriage_chapter_1_summary.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dc914892-a179-4b9a-b159-214e7b149d80/diary_wimpy_kid_new_book.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/36b228a7-89ea-47b6-a1b0-b3d82e83a63b/xezin.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/59aaad2c-1469-4846-8ba7-eca6d6cd9f8f/lakota_woman_mary_crow_dog_summary.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/756269f3-2dec-4890-8ce3-ffcd9299b71e/salton_yogurt_maker_ym9_manual.pdfIn PDF document text
- https://s3.amazonaws.com/vapite/airdroid_premium_untuk_pc.pdfIn PDF document text
- https://s3.amazonaws.com/kagedatabujo/westinghouse_32_led_tv_specs.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e86af3c4-531a-457d-92e0-dff9f48e07e3/kindle_paperwhite_battery_replacement_india.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/84f75309-81da-469e-a332-536065e2b0d4/what_cut_is_steak_tartare.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/220cd050-07d9-48b9-a87d-1c74577e515d/tasenuvojijifuvexawumi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/095ea88c-4bf7-4f5f-a552-9bee249a70a6/tovisapekapibuforug.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/81720c07-ef50-47cc-80f5-3dcc2eecc59e/metapesufifexuruxevuje.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/11f2236a-17dc-4223-aeb1-81188d556164/37228798510.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9da90439-03d9-41d8-a3b4-ae4031362866/applied_calculus_11th_edition.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000104de.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x104DE | 5216 bytes |
SHA-256: 2548b85d7e0b49052134843cf8b5e52e34f627e42a0a4a2432a5cb5f9bf255c2 |
|||
font_01_sfnt_off000116ac.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x116AC | 11108 bytes |
SHA-256: f8c05ae0c60b2d9358ee559f4b8450345ba8c2726aa6b908d20f419be1f76c73 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.