MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged as malicious by a ML classifier and ClamAV, indicating a high likelihood of malicious intent. The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM', with a primary suspicious URL pointing to 'traffking.ru'. This suggests the document is part of a phishing or SEO spam campaign, likely intended to redirect users to malicious sites or download further payloads.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffking.ru/strik?utm_term=pentagon+jr+mask+buy
- https://dugajivesunilo.weebly.com/uploads/1/3/4/8/134866737/1b4cc5c75cd.pdf
- https://cdn-cms.f-static.net/uploads/4495240/normal_5faafc081536c.pdf
- https://winomumamo.weebly.com/uploads/1/3/1/0/131070375/2522629.pdf
- https://static.s123-cdn-static.com/uploads/4460954/normal_5fc75a21017ac.pdf
- https://cdn-cms.f-static.net/uploads/4468819/normal_5faa0f2901aab.pdf
- https://static.s123-cdn-static.com/uploads/4488103/normal_5fc9680223186.pdf
- https://cdn-cms.f-static.net/uploads/4368469/normal_5fbb30d3a5f96.pdf
- https://tivakoxidedopa.weebly.com/uploads/1/3/0/7/130776298/vabovezu-dodamiw-gutagapaz.pdf
- https://satizivuzaked.weebly.com/uploads/1/3/4/3/134383512/mefubiforuvumi.pdf
- https://wipasajumavadus.weebly.com/uploads/1/3/4/7/134775966/7613680.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://static1.squarespace.com/static/5fc14892f9866f3fd2d6f995/t/5fc5cedb3c6ccf69f32886a3/1606799069806/mortal_engines_book.pdf
- https://static1.squarespace.com/static/5fc589c6405d5340f34924f2/t/5fcc18260ab5d62febe0c048/1607211047500/spotlight_room_escape_level_2_paper.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf55524e98326c02077cee/1606374739050/joe_mellen_borehole.pdf
- https://static1.squarespace.com/static/5fe27c48032a635f4054ac28/t/5fe2a169ff1c114acfc702a7/1608687977285/maths_and_physics_tutor_textbook_answers.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000df6f.bin1db39c62ee557ce967dc32791332d5ce9c9961325378dc7432f08bc4c1dc7709 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDF6F | 5356 bytes |
font_01_sfnt_off0000f1a6.binfed7311c72f18ca52e5eef869068a0d5be081d0e8636b8e41e63295a5b0194c7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1A6 | 10896 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.