MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The primary URL points to a suspicious domain ('kuzutuzo.ru') and appears to be part of a larger network of linked PDFs hosted on services like Weebly and Strikingly. This suggests a coordinated effort to manipulate search engine results or distribute malicious content through a link farm. No scripts were extracted, but the PDF structure itself is indicative of malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=what+does+msv+mean+in+running+records
- https://misiwutikamiba.weebly.com/uploads/1/3/4/6/134601431/2f823f8.pdf
- https://turexebino.weebly.com/uploads/1/3/4/2/134265835/288445.pdf
- https://murarukaxew.weebly.com/uploads/1/3/4/6/134666391/befar.pdf
- https://voteweze.weebly.com/uploads/1/3/5/3/135346586/9613514.pdf
- https://static.s123-cdn-static.com/uploads/4369179/normal_5ff5e4c77fa3b.pdf
- https://palisuxil.weebly.com/uploads/1/3/1/0/131071308/5982617.pdf
- https://geridaradekod.weebly.com/uploads/1/3/1/4/131437552/23e84.pdf
- https://dedemapisiwopiv.weebly.com/uploads/1/3/0/7/130775251/fivuleroti-xebifodolabeja.pdf
- https://static.s123-cdn-static.com/uploads/4453105/normal_5ff006681a330.pdf
- https://cdn-cms.f-static.net/uploads/4377128/normal_6042f7084bfcc.pdf
- https://cdn-cms.f-static.net/uploads/4462732/normal_606e57d8f2635.pdf
- https://rupusuji.weebly.com/uploads/1/3/4/8/134878943/sapemenewutas.pdf
- https://wazumiwu.weebly.com/uploads/1/3/6/0/136038811/wedavesomuxoponikip.pdf
- https://kagunalikabogow.weebly.com/uploads/1/3/5/3/135350350/jedepaletikuz-jaguju-wamedugakukipi.pdf
- https://cdn-cms.f-static.net/uploads/4380531/normal_603e90247b4d5.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/a7015b77-e24e-42e9-b5d7-f5a7d4a4f281/fulezidujagoj.pdf
- https://uploads.strikinglycdn.com/files/36cc6ad1-5f38-4884-838c-360807791d11/wigujigikomerova.pdf
- https://uploads.strikinglycdn.com/files/71d3fa2f-3119-4862-8711-0bfb59815246/paint_by_numbers_for_adults_with_frame.pdf
- https://uploads.strikinglycdn.com/files/9602aa93-c80f-4e3d-9eee-e0cdc8428e77/sat_math_score_percentiles.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ff60.bin39b042e248d9975febe9c71c03d0d832ed1f12e456efbd621c69af8eee394df3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFF60 | 5392 bytes |
font_01_sfnt_off0001119f.bin81840363829c12fe43751bff385b62b5f2a2fbe36bdd7e5b22e47e04668e131a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1119F | 10908 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.