MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of external links, many pointing to PDF files, suggesting a link farm or phishing attempt. The embedded URL `https://resalured.ru/wix?keyword=descargar+reminder+apk` indicates a lure related to downloading an application, likely to trick users into visiting a malicious site. No scripts were extracted, but the overall structure and URL patterns are indicative of a phishing or malware distribution campaign.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/wix?keyword=descargar+reminder+apk
- https://betewobinolatid.weebly.com/uploads/1/3/4/7/134756009/sikedadezefaxo-tofotamejid.pdf
- https://fuliwerupemivu.weebly.com/uploads/1/3/5/9/135983247/6339012.pdf
- https://xivovawa.weebly.com/uploads/1/3/4/8/134875493/1396505.pdf
- https://buwumesuja.weebly.com/uploads/1/3/5/3/135303403/7484561.pdf
- http://lotibamuzuti.scienceontheweb.net/greater_anglia_route_map.pdf
- http://jonipifenukiz.mygamesonline.org/french_alphabets_pronunciation_in_english.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/mozedijiz/ximezagizemagusix.pdf
- http://medetoti.epizy.com/mipulerirutoros.pdf
- https://uploads.strikinglycdn.com/files/81a8735b-3b19-42d5-a723-15dd187ee80a/what_is_hadoop_yarn.pdf
- http://kedadav.rf.gd/wezurutizemanapanetawibod.pdf
- https://uploads.strikinglycdn.com/files/a23dc014-5c12-42aa-83be-12e28f798095/65167255314.pdf
- https://uploads.strikinglycdn.com/files/30df60e7-8fbd-48f5-a36f-617257cdb0c2/poxiwimus.pdf
- https://uploads.strikinglycdn.com/files/2dd409ad-01fc-4818-a4d0-179029299c79/hcm_2010_download.pdf
- https://uploads.strikinglycdn.com/files/8adac28d-c3f4-4f83-86fa-f18c19d5db05/how_to_get_purple_splat_hair_dye_out.pdf
- https://s3.amazonaws.com/zerepuzuze/87805330206.pdf
- https://uploads.strikinglycdn.com/files/d24a272d-20eb-408c-bcbe-7bd28d42e16f/dutemowal.pdf
- https://uploads.strikinglycdn.com/files/dd4de5f0-1a20-4b8a-96a1-dc5de6cf15fc/how_to_install_avital_remote_starter.pdf
- http://kavezusi.onlinewebshop.net/daneler.pdf
- https://uploads.strikinglycdn.com/files/742f4d49-d8df-49e6-be49-e9f413dd062a/22303537830.pdf
- https://s3.amazonaws.com/sorapobuk/fps_bypass_pc.pdf
- https://uploads.strikinglycdn.com/files/08c05d4d-78fa-4727-b90d-301843d64184/build_my_life_chords_christy_nockels.pdf
- http://niselekotoz.myartsonline.com/el_aparato_reproductor_masculino.pdf
- https://s3.amazonaws.com/jivagajamav/apercu_bold_italic_font.pdf
- https://s3.amazonaws.com/tiluwisulepam/otterbox_ipad_mini_4_case_instructions.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ef45.bin4d97db0123e4cb150f9399a099d5b3a28ac5fc570abec4a952655c521ded3871 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEF45 | 5424 bytes |
font_01_sfnt_off000101ad.bin33074ae6ab714861c7f35ac1b962a971477911c0df1883292f2186962bb3ac1f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x101AD | 10888 bytes |
font_02_sfnt_off00012701.binc67b92e063456ef988f2cbd1b77901a9218b9c3f1cc1011e90b95a493366add5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12701 | 16368 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.