MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of external links, many of which are embedded within the document body and appear to be part of a link farm designed to direct users to potentially malicious sites. The primary URL identified, 'https://xezojetit.ru/strik?utm_term=microsoft+technical+program+manager+interview+questions', suggests a phishing lure related to job interview preparation.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/strik?utm_term=microsoft+technical+program+manager+interview+questions
- https://cdn.sqhk.co/gitovera/Q8jfRgg/57351314682.pdf
- https://rebodegumirimak.weebly.com/uploads/1/3/0/7/130775130/3bac11.pdf
- https://cdn.sqhk.co/gisepavuv/hcrf9i0/18391104313.pdf
- https://xekukagakodepa.weebly.com/uploads/1/3/3/9/133999272/217095.pdf
- http://localdesign.me/48874270458egtfr.pdf
- https://cdn.sqhk.co/dikozogub/ggEghzi/murelokaj.pdf
- https://cdn.sqhk.co/nujidegowupi/jijAuSZ/rijopuwesovenibeg.pdf
- http://susurrus.space/igcse_maths_formula_bookletxtjhw.pdf
- https://banukusisazej.weebly.com/uploads/1/3/4/8/134893357/174390.pdf
- https://dizorewumuzesab.weebly.com/uploads/1/3/4/0/134012942/fepaxoluf.pdf
- https://nasavizar.weebly.com/uploads/1/3/5/3/135322571/fanuw.pdf
- https://cdn.sqhk.co/gabadifofibo/jfhiAji/76801394658.pdf
- https://cdn.sqhk.co/guledijuxi/ibhjhgD/jejavosawumupaxinikufu.pdf
- https://cdn.sqhk.co/numiwuzuwix/CXhgYcY/mimpi_hamil_anak_laki_laki_kembar.pdf
- https://cdn.sqhk.co/soxuvezosapa/XTjjKhd/14271222329.pdf
- https://cdn.sqhk.co/wujozuzewed/jjgLjhv/drift_cup_racing_mod_apk.pdf
- https://xaxusadusu.weebly.com/uploads/1/3/4/4/134497069/a141f3678e9f.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/5836233e-7600-4092-9a11-d0107c1e2bfa/where_can_i_buy_fire_and_ice_condoms.pdf
- https://uploads.strikinglycdn.com/files/51e13a8a-2beb-4fd4-a2e6-b0ee17a51df0/koraf.pdf
- https://uploads.strikinglycdn.com/files/b1d2677c-063c-4d02-8607-525847ce324f/genesu.pdf
- https://uploads.strikinglycdn.com/files/3d9a5f99-d91a-4e50-8d3b-68ea793f506a/free_willy_4_trailer.pdf
- https://uploads.strikinglycdn.com/files/fd081785-faed-4fbc-a094-122aeafc9966/miveratazoz.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e872.binf2bc0783825cdde6ed0ea31c4d7352c19f0fce26cfccc65d80b3b90390a6b4c8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE872 | 5712 bytes |
font_01_sfnt_off0000fbdb.bin09c9c31ed7448eeeaec27c496824490f84725898f48a5af692bb06e3cbf799d0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFBDB | 10616 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.