MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various URLs. One prominent URL, 'https://resalured.ru/strik?utm_term=how+do+animals+store+excess+energy', is directly embedded and flagged as an external URI. ClamAV also detected this file as 'Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0', strongly suggesting a phishing or malicious intent. The ML classifier output of 0.999208 further supports the malicious classification.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/strik?utm_term=how+do+animals+store+excess+energy
- https://cdn-cms.f-static.net/uploads/4457876/normal_602aec0e2e9ab.pdf
- https://static.s123-cdn-static.com/uploads/4492593/normal_5fdcb86d7639d.pdf
- https://static.s123-cdn-static.com/uploads/4387922/normal_5fe4577220db0.pdf
- https://cdn-cms.f-static.net/uploads/4426819/normal_6014d58d27d41.pdf
- https://xelewutoritawi.weebly.com/uploads/1/3/1/0/131070131/565c01def151f94.pdf
- http://rrrrkkkkk.space/favubosuuzso.pdf
- http://winoorama.site/2015_audi_q7_maintenance_manualghnxj.pdf
- http://trickyturkey.com/toveziretovwkr7o.pdf
- http://floradoma.net/umbrella_academy_apocalypse_suite_download2x249.pdf
- http://wisitens.online/microsoft_word_format_painter_shortcut_keynqoqr.pdf
- https://mirajaxudedina.weebly.com/uploads/1/3/0/7/130775596/tonoxajipu.pdf
- https://static.s123-cdn-static.com/uploads/4404976/normal_5fca4abf35070.pdf
- https://static.s123-cdn-static.com/uploads/4480149/normal_5ff260b6bf150.pdf
- https://ponuwusareti.weebly.com/uploads/1/3/1/6/131636782/redufuda-tusadigogud.pdf
- https://cdn-cms.f-static.net/uploads/4422373/normal_603542fa9199e.pdf
- https://cdn-cms.f-static.net/uploads/4487647/normal_601117dcc58ee.pdf
- https://folodekoj.weebly.com/uploads/1/3/2/8/132814523/jogalutugefinud.pdf
- https://romevezijije.weebly.com/uploads/1/3/4/7/134756673/aa6cbc23.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/f34565a9-3828-4e0f-b700-2f7cb9d85060/what_type_of_oil_for_gy6_150cc.pdf
- https://uploads.strikinglycdn.com/files/b9b13bd1-b6c4-43c5-9658-3013e0b7fcbd/a_discovery_of_witches_season_2_episode_8_recap.pdf
- https://uploads.strikinglycdn.com/files/301800fb-61d6-4081-a477-bdbb6fafbd0c/rmv_drivers_permit_application.pdf
- https://uploads.strikinglycdn.com/files/dcd47466-33eb-4a53-90b2-a11175ea0302/92984128886.pdf
- https://uploads.strikinglycdn.com/files/f5773173-4fa5-4b5b-bc9a-0f884aacdce7/how_to_setup_vizio_36_2.1_soundbar.pdf
- https://uploads.strikinglycdn.com/files/7bc38ea3-5e10-4eee-ba2a-202c45a7a2b8/vozabojimakudo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010248.binfa3955cd28cfdce08963c1bca15f698c66dc11e832856a3e0e1772c83457bfe7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10248 | 5480 bytes |
font_01_sfnt_off000114eb.binbac53d61b383da054bced1259c5252e27548bd10ed58fc9b920c007dbd933729 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x114EB | 11648 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.