MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains numerous external links, a technique often used for SEO-based link farms or phishing lures. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, suggesting an attempt to drive traffic to malicious or compromised sites. The ML classifier and ClamAV detection further support its malicious nature, likely as a phishing or trojan delivery mechanism.
Machine Learning
- Nyx PDF Classifier malicious score 0.9908
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/award?keyword=musculos+de+la+articulacion+dela+rodilla+pdf
- https://static.s123-cdn-static.com/uploads/4500453/normal_5fc8d621444e3.pdf
- http://disclosures.space/physical_science_grade_12_study_notep05i3.pdf
- https://cdn-cms.f-static.net/uploads/4446643/normal_6010890a3a876.pdf
- https://cdn-cms.f-static.net/uploads/4484994/normal_5fda4042c22b4.pdf
- https://dorizusedi.weebly.com/uploads/1/3/0/7/130776489/5797365.pdf
- https://cdn-cms.f-static.net/uploads/4491936/normal_600f90bbde57e.pdf
- https://cdn-cms.f-static.net/uploads/4478378/normal_60146b39a0472.pdf
- https://cdn-cms.f-static.net/uploads/4476142/normal_6010c92b6fd80.pdf
- https://ximapufem.weebly.com/uploads/1/3/1/4/131437784/57eb30.pdf
- https://cdn-cms.f-static.net/uploads/4456122/normal_5fe6f6da8e67e.pdf
- https://cdn-cms.f-static.net/uploads/4454561/normal_603fea25f0d5a.pdf
- http://copyrightmediahelp.com/37229699005mlrjq.pdf
- https://75e6061f-eb7a-4ce8-b546-077bf96366c3.filesusr.com/ugd/2dfd19_cde93316b85e4df4876603cb3d0417ea.pdf?index=true
- https://s3.amazonaws.com/wizidimawag/jimuwasemiwojawima.pdf
- https://s3.amazonaws.com/lejivugeleguwod/halloween_factoring_worksheet_answer_key.pdf
- https://c1d61d78-9bae-425c-b347-ee91470fe4f1.filesusr.com/ugd/60933b_209927a9e71e4a39a125fba69c11f95c.pdf?index=true
- https://e42ce0b3-f376-4cb5-9abe-507fdbb9570c.filesusr.com/ugd/603474_7631f68e912c4d2e82e4b677631b7a37.pdf?index=true
- https://s3.amazonaws.com/jizubisetebof/85834468739.pdf
- https://bef89f6e-6323-4b84-ad9d-a44490bfcc4f.filesusr.com/ugd/96768c_de6e47abff65496fa1fa166c3de4c82f.pdf?index=true
- https://b40f07b9-a98f-42b6-a6e2-5dc2c82ebb0e.filesusr.com/ugd/e949ea_eb361d18a7674613b1f11892d112ef38.pdf?index=true
- https://s3.amazonaws.com/woneketelak/realidades_1_capitulo_7b-_2_answers.pdf
Open this report in the interactive analyzer, or submit your own file for analysis.