MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains numerous external links, with a primary suspicious URL pointing to 'jumiwimov.ru'. The PDF structure suggests it's designed to host a link farm, likely to redirect users to malicious content or phishing sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/123?utm_term=c+template+function+pointer+return+type
- https://futibiwis.weebly.com/uploads/1/3/1/4/131408183/6181081.pdf
- https://juvinegedixipa.weebly.com/uploads/1/3/1/6/131637649/6aa7892bcceba3a.pdf
- https://vudexugir.weebly.com/uploads/1/3/2/7/132710723/5adc6f6b5c0688.pdf
- https://tugemizibu.weebly.com/uploads/1/3/0/7/130739278/poxeserito.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- http://mifimoruzuwo.pbworks.com/f/5750678473.pdf
- https://uploads.strikinglycdn.com/files/e7e2f75f-4fba-499c-8898-dedcea8895a7/titufixupalikumefedizixok.pdf
- http://rixepal.pbworks.com/f/70693936546.pdf
- https://uploads.strikinglycdn.com/files/42e287c7-52fd-41fa-a7fa-82952a29f6b4/73407513208.pdf
- https://uploads.strikinglycdn.com/files/5d7c0314-c692-4c19-ba91-e885122c9f08/vepakenarimasojesax.pdf
- http://najapenoz.pbworks.com/w/file/fetch/144545745/15466788273.pdf
- https://uploads.strikinglycdn.com/files/87e53364-bfd8-4329-84a7-76a26ac3c166/jotonopapufezut.pdf
- https://uploads.strikinglycdn.com/files/e14fe695-a254-43a5-819f-29c4b7f74295/32065653474.pdf
- http://siruzosu.pbworks.com/w/file/fetch/144453273/how_is_the_praxis_plt_7-12_scored.pdf
- http://bupataved.pbworks.com/w/file/fetch/144420834/writing_algebraic_expressions_from_word_problems_worksheets_6th_grade.pdf
- https://uploads.strikinglycdn.com/files/de8d0869-eb93-4e34-9a12-9ab2595ea0e0/82623949034.pdf
- https://uploads.strikinglycdn.com/files/ea5497e3-2e2d-4b93-9b9f-221c08c1887c/descargar_mix_los_tucanes_de_tijuana_corridos_al_100.pdf
- https://uploads.strikinglycdn.com/files/3964a5ef-dd66-477d-9855-6c2913f06006/58088294920.pdf
- http://xelivolofuso.pbworks.com/w/file/fetch/144548193/genotuxotewama.pdf
- https://uploads.strikinglycdn.com/files/7338a5b7-a580-4eab-a810-561e5d1566bd/troy_bilt_weed_eater_head_parts.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ed3a.bin0bef6f16b27ba16e52bab949740e0366016ac6f0cc39bd27e86e7d38ca85458a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED3A | 4988 bytes |
font_01_sfnt_off0000fe26.bin3b8265983916b3ed9c21bd1bed6218bd8920fdc93cb09e8ebced51dfd17870dc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE26 | 11420 bytes |
font_02_sfnt_off00012565.bin05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12565 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.