MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with a significant heuristic firing indicating a 'PDF_SEO_LINK_FARM' and 'PDF_SEO_UTM_REDIRECTOR_LINK'. The primary malicious URL identified is 'https://vilenefex.ru/strik?utm_term=selenium+webdriver+in+c%2523.net', which appears to be an SEO redirector used for phishing or malware distribution. The ML classifier and ClamAV detection strongly indicate maliciousness, supporting a phishing attack pattern.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/strik?utm_term=selenium+webdriver+in+c%2523.net PDF link annotation
- https://pizugonuju.weebly.com/uploads/1/3/1/8/131856050/fezipaxe_velunosozov_zifiguwetogowu_volozibasa.pdfIn PDF document text
- https://patapirebitogi.weebly.com/uploads/1/3/0/8/130814085/1225958.pdfIn PDF document text
- https://nujirami.weebly.com/uploads/1/3/1/3/131384028/nozabitexigexu-nabagamazowe.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://7ae52be2-ba3c-41fb-8935-29281088223e.filesusr.com/ugd/affaa6_3d530b4d0bed4a2f97552b4aa9e04284.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/1e0a24fb-e45e-414c-ab35-e9f0a105a6cf/modomipibepe.pdfIn PDF document text
- https://s3.amazonaws.com/tinivukedeta/58976341675.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a079a956-58ee-486f-8def-d03060ce47d0/zapixojubuzezafozepedaxiv.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ae78506b-4683-48a7-b119-fd583949eff9/disejolezawidovekubofo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1e3dd76a-a10b-4b6c-9111-c26a3e176a1f/odyssey_summary_book_9_and_10.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a3a2c02b-91da-4305-910b-15157f6b07b8/icd_10_code_for_compression_fracture_third_lumbar_vertebra.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5b6bcc73-6d1b-4342-8d20-a54641909816/kef_r7_price_singapore.pdfIn PDF document text
- https://5e9816b5-e261-4a84-a5c7-594b6999e1c8.filesusr.com/ugd/eb2f7d_9d2a443cbe5841fd8a31540707857161.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/lakujusitejojet/feribuvu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/627aeae7-9bfc-4472-a23a-15793140d977/xujovuzaroguxepajuf.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9a4caba5-40dd-4b85-8374-2ac32da837aa/37679208810.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2fff1cf1-ac15-44ad-8b03-b48a91c232fc/dupotin.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6a80e6cb-1ae6-4f16-a75b-80ad8452f09b/85820036023.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/544f4814-589f-4eab-bae7-1c4bcb3fbdf5/kevowofegalif.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a4be1263-94b6-48ed-86c7-92d29e5b57db/called_out_by_barbara.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f879c1f6-2212-4b16-9f5d-b7fcdc26155a/dujepodekafeges.pdfIn PDF document text
- https://s3.amazonaws.com/xasovewipeje/focal_seizures_treatment_guidelines.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f3a9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF3A9 | 5092 bytes |
SHA-256: 2e4d616343f86c287b2d6e4a43a5f36b2234384ecafb26e28a17c4ce082630b7 |
|||
font_01_sfnt_off000104fc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x104FC | 11024 bytes |
SHA-256: 5b597af39f5e80c690973669ca46b794ef0e119b3650442e00cf690f1db76e15 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.