MALICIOUS
124
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains numerous embedded URLs, many of which point to disposable hosting and are part of a link farm, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or delivering a secondary payload. The document body's deceptive title about chargeback rebuttals is a common lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9476
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://oniceh.ru/pbw?utm_term=how+do+you+write+a+chargeback+rebuttal+letter
- https://doxigexuwalo.weebly.com/uploads/1/3/4/7/134708718/sawunek_tajamug_tijujovot.pdf
- https://static.s123-cdn-static.com/uploads/4427103/normal_5fee4729c32a6.pdf
- https://static.s123-cdn-static.com/uploads/4494430/normal_5fcddebb174f8.pdf
- https://jomigotub.weebly.com/uploads/1/3/4/7/134748998/390407.pdf
- https://cdn-cms.f-static.net/uploads/4459170/normal_601eea053ad7c.pdf
- https://cdn-cms.f-static.net/uploads/4483851/normal_600ccd07a991d.pdf
- https://static.s123-cdn-static.com/uploads/4389801/normal_60006b88278ca.pdf
- https://melejorun.weebly.com/uploads/1/3/0/7/130775242/newebax.pdf
- https://ronuviwa.weebly.com/uploads/1/3/4/5/134587060/f0ed3d4.pdf
- https://gapuromediwav.weebly.com/uploads/1/3/0/8/130814643/4339073.pdf
- https://cdn-cms.f-static.net/uploads/4450042/normal_606c4aafacebd.pdf
- https://cdn-cms.f-static.net/uploads/4453734/normal_6067de0bb03e9.pdf
- https://cdn-cms.f-static.net/uploads/4415073/normal_6016fd530d4a0.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://siruzosu.pbworks.com/f/bhojpuri_film_3gp_full_movie_download.pdf
- http://mizunebapod.pbworks.com/w/file/fetch/144466734/33292300456.pdf
- http://jotoxipigi.pbworks.com/w/file/fetch/144455022/81444328284.pdf
- http://kipizasuzeda.pbworks.com/f/perfumes_the_a-z_guide_2018.pdf
- http://niwomif.pbworks.com/f/lirolumi.pdf
- http://naxenuve.pbworks.com/f/my_stupid_boss_2_lk21_indoxxi.pdf
- https://uploads.strikinglycdn.com/files/804ab083-6e65-4c4f-bbfc-d6f347e9b99b/sex_education_season_2_episode_recap.pdf
- https://uploads.strikinglycdn.com/files/0317b553-e9e8-48a0-8103-35501a2c567a/gloomhaven_spellweaver_guide_imgur.pdf
- http://gosirata.pbworks.com/f/how_to_find_alien_containment_in_subnautica.pdf
- http://xalomuzavege.pbworks.com/w/file/fetch/144459036/crossover_ccat_test_answers.pdf
- http://sepaxebi.pbworks.com/f/fire_evacuation_plan_template_for_warehouse.pdf
- https://uploads.strikinglycdn.com/files/04ad13d3-e0f8-410d-90a4-411f601a701d/thesaurus_of_scales_and_melodic_patterns.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000103e1.binc3eadc47db603c6336337255d29f7be172bde15adbfdd8a9d4f4f78df009a140 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x103E1 | 5380 bytes |
font_01_sfnt_off0001163f.bind6da702710e0a9000e7f460a2d7b73f2c16c8275eb1fe4593ebbe293eef777f6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1163F | 11788 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.