MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document contains a large number of external links, many of which are hosted on disposable domains, suggesting a link farm or phishing attempt. The primary URL points to a search result for 'Attack on titan full movie free download', indicating a lure to trick users into clicking malicious links. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9960
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://philabc.ru/pbw?utm_term=attack+on+titan+full+movie+free+download PDF link annotation
- https://cdn-cms.f-static.net/uploads/4455179/normal_6013350b95420.pdfIn PDF document text
- https://tojoxuponoseb.weebly.com/uploads/1/3/5/3/135395296/rebokokaz.pdfIn PDF document text
- https://mozufutedubido.weebly.com/uploads/1/3/4/5/134503110/ac903.pdfIn PDF document text
- https://fuzaterolipi.weebly.com/uploads/1/3/1/4/131438829/8942711.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366339/normal_6066b7c1ec72c.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4481056/normal_5fe15419c8341.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4472200/normal_5fdb338e6c813.pdfIn PDF document text
- https://kuxubujokug.weebly.com/uploads/1/3/0/7/130775750/b9320.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4484610/normal_603b36a832d28.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/b387b9ac-7fc5-402f-b460-18ed6dda7345/batman_death_in_the_family_2020_rotten_tomatoes.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9c092961-309e-4493-88f4-51842f628a85/total_gym_platinum_plus_attachments.pdfIn PDF document text
- http://luwivaj.pbworks.com/w/file/fetch/144784884/9._snf_kimya_palme_yaynlar_soru_bankas.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d990293f-cb7f-47a9-8213-6659519908df/ensayo_sobre_la_pelicula_los_piratas_de_silicon_valley.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/91d5b8da-c5f8-43c2-a0de-1e349636d894/26987476324.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b1fc92a0-4534-421a-9a69-bd59d2ee9bb7/norcold_rv_fridge_repair.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3825f8b4-b94b-4b45-b890-c951f6d6090c/6903775522.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/af97c41d-dcef-477b-a638-c5f9a950c886/dakopefatovodav.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/784e4eda-0589-418d-aef7-c295293554a7/79039005929.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/22e1afeb-616e-4927-8be4-9839df196848/xujozage.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2a4984e1-b8f9-466f-9e3b-57a1b4b6feee/flowers_for_algernon_characterization_chart.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1cec9471-e9f6-407e-b32c-18abdb81fead/young_living_essential_oil_recipe_book.pdfIn PDF document text
- http://jitijaloj.pbworks.com/w/file/fetch/144524973/73842329941.pdfIn PDF document text
- http://barumena.pbworks.com/f/97505314124.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3f60dee4-4253-4d00-93bd-26239d1c6174/how_to_connect_hp_deskjet_2652_to_wifi_network.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ee2fd902-781c-4cdb-a635-00f4f266424c/varonupe.pdfIn PDF document text
- http://zuvuzut.pbworks.com/f/manfaat_dzikir_la_ilaha_illa_anta_subhanaka_inni_kuntu_minadzolimin.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ea8c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEA8C | 5196 bytes |
SHA-256: 6188556a641004c2c21940cac9bde5f072b233bf729f13ab8497b79471db5e1b |
|||
font_01_sfnt_off0000fc3e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC3E | 10692 bytes |
SHA-256: 15069762b7ea4b4c44f2d1ce8348eac81b4b90ac1b0539bdc7ac58ca15d8bad1 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.