MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a large number of external links, many pointing to potentially malicious or SEO-manipulated content, as indicated by the 'PDF_SEO_LINK_FARM' heuristic. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were explicitly extracted, the presence of embedded URLs and the nature of the link farm point towards a phishing or malicious redirection scheme.
Machine Learning
- Nyx PDF Classifier malicious score 0.9414
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://bologen.ru/aws?utm_term=cdsco+guidelines+for+bioequivalence+studies PDF link annotation
- https://site-1241632.mozfiles.com/files/1241632/faxevinafu.pdfIn PDF document text
- https://site-1171658.mozfiles.com/files/1171658/samsung_edge_lighting_apk_xda.pdfIn PDF document text
- https://site-1178961.mozfiles.com/files/1178961/trick_shot_challenge_ideas.pdfIn PDF document text
- https://fisadurubimu.weebly.com/uploads/1/3/1/4/131409264/0772b267f.pdfIn PDF document text
- https://site-1193774.mozfiles.com/files/1193774/34087910075.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4448137/normal_5fcd56002e2fd.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4423699/normal_5ff4dcb480e16.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4413573/normal_5fe2501b0a1a0.pdfIn PDF document text
- https://site-1174390.mozfiles.com/files/1174390/94790526006.pdfIn PDF document text
- https://site-1220888.mozfiles.com/files/1220888/keep_away_from_runaround_sue_chords.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4391015/normal_5f91354f78ede.pdfIn PDF document text
- https://s3.amazonaws.com/wulotugadag/free_borland_delphi_7_full_crack.pdfIn PDF document text
- https://s3.amazonaws.com/zozofufulolig/66767432413.pdfIn PDF document text
- https://s3.amazonaws.com/jarawaxanivu/75119541960.pdfIn PDF document text
- https://s3.amazonaws.com/jinotugiwomo/free_coloring_worksheets_for_kindergarten.pdfIn PDF document text
- https://s3.amazonaws.com/nitirew/windows_10_latest_iso_free.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.