MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file is identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, many pointing to disposable hosting, suggesting a link farm designed to redirect users to malicious sites. The document body, though heavily obfuscated, appears to be a lure related to 'Estilos de afrontamiento en adolescentes pdf'. No scripts were extracted, but the presence of numerous external URLs and the overall structure strongly suggest a phishing or content-scraping attack.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/123?utm_term=estilos+de+afrontamiento+en+adolescentes+pdf PDF link annotation
- https://static.s123-cdn-static.com/uploads/4387232/normal_5fee6e7a28bb4.pdfIn PDF document text
- https://lafapimiwegu.weebly.com/uploads/1/3/4/0/134041150/balujuwuke.pdfIn PDF document text
- https://kivobuduzuv.weebly.com/uploads/1/3/0/7/130739084/xejaruner-sufimaz-bajofipoda-zinigogo.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4408343/normal_600247a5853a6.pdfIn PDF document text
- https://foxogitasi.weebly.com/uploads/1/3/2/7/132740511/67ac08a9534.pdfIn PDF document text
- https://xopomosafeg.weebly.com/uploads/1/3/4/7/134732974/zojama_pemamobeza.pdfIn PDF document text
- https://wabuxopimigom.weebly.com/uploads/1/3/4/0/134042903/7812233.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4496582/normal_602783504459b.pdfIn PDF document text
- https://vowebaxuzifov.weebly.com/uploads/1/3/0/7/130738870/ponivomatexago-mowaduzajirilup.pdfIn PDF document text
- https://valiwuvubeke.weebly.com/uploads/1/3/4/6/134694219/a389cf3.pdfIn PDF document text
- https://fevuvewuvadudu.weebly.com/uploads/1/3/4/6/134650824/wukud-fakat-zumodiginofuk.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/c0124ac4-e017-4b77-a5a6-ddf3cb7e394f/being_happy_tal_ben_shahar_free.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/abf3d8bd-8f1b-4b32-b6b2-d6c363a341b6/can_you_use_rental_income_for_fha_loan.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/66d557c6-39b8-457d-9962-bf3d9e1e0774/how_to_reset_ink_epson_l3110.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c62eeb8b-dc0b-4c13-8082-3d162b2eb8a6/jowizagi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7109761d-7c8f-4fec-901d-f3a962e2dc43/bombastic_words_for_essay.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a11f3fb2-1061-4bb3-b133-9f3dda2edf1f/illustrator_minimum_system_requirements.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cff77f3f-b5d3-488f-a47d-4ca7d73924a2/The_final_barber_shop_Amsterdam_Avenue_New_York_NY.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00012d1b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12D1B | 5256 bytes |
SHA-256: b9002fd899dcd7ee866bfc2f3d74df889442342fe89e836b6e3001af2914ee48 |
|||
font_01_sfnt_off00013ef0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13EF0 | 12296 bytes |
SHA-256: 42183e63bbf0b60d4935dbd5f0ba61d78006173b2bc9565bda5ca0b045c7d425 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.