MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, a common tactic for link farms or phishing campaigns. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as a phishing trojan. While no scripts were directly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to potentially harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/123?utm_term=android+9+call+recording+root
- https://cdn.sqhk.co/xubipoxeguza/jeOiii6/dirt_bike_unchained_how_to_do_tricks.pdf
- http://tapagigozi.medianewsonline.com/april_2020_current_affairs_free_download.pdf
- https://cdn.sqhk.co/bovokolel/NQDhj90/muvimadevizemojuf.pdf
- https://cdn.sqhk.co/lokabawopup/ifcvBI3/skater_girl_aesthetic_makeup.pdf
- http://goxamid.mypressonline.com/successful_git_branching_model.pdf
- http://xomutukegadoj.mypressonline.com/milumorawexu.pdf
- http://forovasax.medianewsonline.com/42634042896.pdf
- http://rixorevu.getenjoyment.net/logitech_z_5500_subwoofer_replacement.pdf
- https://cdn.sqhk.co/sixitigoxeto/hcuzif1/55719577158.pdf
- https://cdn.sqhk.co/mudewaxiv/1EiFhdR/rationalizing_denominators_worksheet_answer_key.pdf
- https://cdn.sqhk.co/gulifunanale/Djfgcoo/flight_pilot_simulator_3d_apk_mod.pdf
- https://cdn-cms.f-static.net/uploads/4411479/normal_606c4c8e6d39f.pdf
- https://cdn.sqhk.co/tatidukigag/0hbjhhb/battleship_north_carolina_wilmington_nc_28401.pdf
- https://cdn-cms.f-static.net/uploads/4454807/normal_6044e5a57356d.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://54179944-c6a3-49b3-9462-5d1939b6aff2.filesusr.com/ugd/49f5ef_d2c3db6192e34bf493d62986eb60a5f5.pdf?index=true
- https://13a7c488-548c-4b48-b567-d2b0b9a3e1de.filesusr.com/ugd/85d67f_5f9f5919f6784de1b349208d4793ac7a.pdf?index=true
- https://87da31d5-d184-45e7-a456-0ad082c8bd65.filesusr.com/ugd/55e94a_b01e591d0c3449be97138d89a5e23159.pdf?index=true
- https://42f4b946-f871-4f2a-a73e-6571c6569919.filesusr.com/ugd/e20521_fcaf36694ea84cd1a96109f6e8012428.pdf?index=true
- https://748e62c5-a849-4dff-87e7-3b5f74cb3522.filesusr.com/ugd/0df896_2b5471cc08874073b1ff2ead8619938d.pdf?index=true
- http://vujijemu.atwebpages.com/assured_wealth_plan_yes_bank.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ea9c.bin28ed794e72b97bf54b00addc40bf08dbe6dba7fd1b279c836746c3e745707fed |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEA9C | 5072 bytes |
font_01_sfnt_off0000fbef.bineea6c0e874f8f60dd5d8ed0d6193fb7d81ef82a43c303f08f0ecf9e017827ee5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFBEF | 11776 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.