MALICIOUS
194
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. It uses an urgency-based lure. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/strik?utm_term=jedi+apprentice+the+rising+force PDF link annotation
- https://kolokizegilo.weebly.com/uploads/1/3/4/3/134370221/wamad.pdfIn PDF document text
- http://medyahanem.com/63928816571xjapi.pdfIn PDF document text
- https://disovipogazita.weebly.com/uploads/1/3/1/3/131398104/1128b24c.pdfIn PDF document text
- https://cdn.sqhk.co/texekikevow/iiKKYig/nostalgia_ice_cream_maker_recipes.pdfIn PDF document text
- http://swiss-gear.store/big_data_analytics_salaryce06f.pdfIn PDF document text
- http://on24-system.club/bloons_tower_defense_3_download_fulla2iv2.pdfIn PDF document text
- https://cdn.sqhk.co/kivutuzo/mMumif2/alone_marshmello_remix_slushii.pdfIn PDF document text
- https://cdn.sqhk.co/majumoros/fVgiheg/forgotten_tales_rpg_quest_guide.pdfIn PDF document text
- https://cdn.sqhk.co/dojarodawiw/jbzXgfN/sharpening_stone_grinding_wheel.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://bad3f395-1638-4667-b349-d6f934eeab49.filesusr.com/ugd/ed2d23_4a442d6c6fdd405b9df9398ede9540db.pdf?index=trueIn PDF document text
- https://740e8036-3174-4dac-ae20-9eee1cd11a0a.filesusr.com/ugd/0f1c31_c406dbcbb64c4d60a364b7e49f783822.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/fedf7f78-bc45-4e39-a169-021fde899e4d/89448706005.pdfIn PDF document text
- https://ff5d1526-1eb9-447d-8915-67ca9933f1b4.filesusr.com/ugd/9565fd_11cfb46a12b545138ec9653e26086cf9.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/b042f10e-8f4e-46da-be6b-d6a861b4d731/solving_trigonometric_identities_worksheet_with_answers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c53571fe-47a6-402b-b8d4-4483e905474d/momagokalij.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/06ce7297-ec23-4080-9704-15c1dee076dc/how_to_induce_labor_sims_4_2019.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a28314c2-58b5-4fbc-aab2-288ae9103114/82475943371.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/54dfa2c1-2b36-44a7-9b0b-b4e3a6ffbfbf/51223964243.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/069eed1f-d824-4986-ae17-10d153883f86/what_are_the_basic_tenets_of_humanistic_psychology.pdfIn PDF document text
- https://acaa17bf-cf2e-4132-a9e9-810271eb8bc4.filesusr.com/ugd/ab5b4c_a1b9cafc252c4d9b8b71c01184c88e63.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/d645581d-8c42-44e2-93cc-4f94deb1af94/take_ivy_cuttings.pdfIn PDF document text
- https://42f4b946-f871-4f2a-a73e-6571c6569919.filesusr.com/ugd/e20521_e379d81626fa4ebd878edf7aafb14d91.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010807.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10807 | 5372 bytes |
SHA-256: 8a4b2384379b0ed734ec9c915bb6d14d7827b88a9adbb1984fcb3a838cd44ef1 |
|||
font_01_sfnt_off00011a49.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11A49 | 13000 bytes |
SHA-256: f3ae96c2bc19fc3de99449cf4ab3beda9d156efafd8f3de69b3f9e8c394cf100 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.