MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The primary malicious activity observed is the redirection to external URLs, such as 'http://voirlo.xyz/81274333875gun75.pdf', which is a common tactic for phishing or distributing further malware. The ML classifier and ClamAV detection strongly suggest malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/award?keyword=all+about+space+august+2020+pdf
- http://voirlo.xyz/81274333875gun75.pdf
- http://smotrikino.fun/269958167800ty69.pdf
- http://changepass.online/ukulele_strumming_patterns_4_4d4fg6.pdf
- https://zujogomute.weebly.com/uploads/1/3/1/4/131483029/nowufejejumago.pdf
- https://kaledawuvilef.weebly.com/uploads/1/3/4/7/134727412/6448f.pdf
- http://fdvsefwfrw.space/34754058060swe8q.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cfc603e6-7cd4-4c42-812b-9722deb80ae4.filesusr.com/ugd/0e9fc2_e2d5713d39324a4b93c6ae018cd2b64a.pdf?index=true
- https://s3.amazonaws.com/tutapaxi/45169375017.pdf
- https://3bcdeb60-9876-4d14-bc0a-1dd1632c647c.filesusr.com/ugd/16a96a_685bfda4a6a9435dbcd2aa6037612b0c.pdf?index=true
- https://8cff94d3-ecab-4ea5-ad27-d3e67d02fd32.filesusr.com/ugd/2813e2_c4b15670dee647c1bce5f86471d4e64c.pdf?index=true
- https://uploads.strikinglycdn.com/files/6ac165dc-c1ac-40ff-8b3f-6836dc05783c/29662739328.pdf
- https://s3.amazonaws.com/widuxade/9265153296.pdf
- https://0aed7b51-d02b-4864-a6bb-b478bb809667.filesusr.com/ugd/fbdaab_4c4997cf3ebb47019b2bf3c94da80dad.pdf?index=true
- https://5984e891-aecd-43e6-866f-efdb297c9c35.filesusr.com/ugd/403565_661807cf47824be4b0c9e2491462d07b.pdf?index=true
- https://uploads.strikinglycdn.com/files/cc424dd8-f37e-4290-83d4-5bc84c426833/dragon_world_game_mod_apk.pdf
- https://uploads.strikinglycdn.com/files/422ff3c1-fddf-4f0f-9d24-55bd78bbd16d/9919321984.pdf
- https://7a512b58-7189-4bc4-8343-f643fa9054c9.filesusr.com/ugd/1e52da_15781663784f451790cdc2af63656955.pdf?index=true
- https://93dbb2ad-f1e8-4c6c-adfd-2ef134399473.filesusr.com/ugd/df4650_7c719da82dfe458d86a09b490c1c0bba.pdf?index=true
- https://58f604bd-1fd8-4cfe-af9b-f15e67d030d5.filesusr.com/ugd/9a7439_cc1fc900199d425a86a70c3e1368755a.pdf?index=true
- https://6b2d4799-12fc-456d-8881-596234ac9a0a.filesusr.com/ugd/ae8ff6_95358e02dc9f49ddb8c90d8fae130186.pdf?index=true
- https://s3.amazonaws.com/setikizo/82629319530.pdf
- https://4cd5a77a-be8d-44ba-8952-4177873115c4.filesusr.com/ugd/930050_90f6a75f0b7a48f69a490b442fe65912.pdf?index=true
- https://uploads.strikinglycdn.com/files/fba3fd82-46ec-4f18-bb50-f52c68c458dd/how_do_i_find_out_my_drivers_license_id_number.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fe54.bincfe68b8d542fa3bb02b47d08e3949d5983f522409108f3e6f5d41d4837e8d129 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE54 | 5628 bytes |
font_01_sfnt_off00011192.bin9c1f99f9ed0426ea4af08499383472db9b684eefb9d2e216defd466e3f395c57 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11192 | 11664 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.