MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9961
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/strik?utm_term=law+of+property+act+1925+section+205 PDF link annotation
- http://legko.travel/ragetagolejisofotobunom7age.pdfIn PDF document text
- http://litvinenko.xyz/ruferiwezippp9yg.pdfIn PDF document text
- https://pumizisumene.weebly.com/uploads/1/3/4/0/134017803/togetirirukukemu.pdfIn PDF document text
- https://kogemujifogez.weebly.com/uploads/1/3/4/3/134344524/4758238.pdfIn PDF document text
- http://gelchlen.fun/fewinexegasupapune7ie.pdfIn PDF document text
- http://lovelyhouse.online/kojoxibofoxibagenunonawa6tckw.pdfIn PDF document text
- https://fabavowugofafif.weebly.com/uploads/1/3/4/5/134591931/ritim-gekitatu-dezavivatuxen.pdfIn PDF document text
- https://bojomuse.weebly.com/uploads/1/3/4/4/134462584/3f6294629ec8f.pdfIn PDF document text
- https://batagokefo.weebly.com/uploads/1/3/1/0/131070859/lazowuginipe_vawunaxuwu_bowefu_gugikid.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/a5cba9fe-5d3d-4b2d-aea8-7eaf77a5b485/kaduxovereg.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6fd84f27-20d8-4e43-a143-799a1aa34eef/multiplication_word_problems_grade_4_khan_academy.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d3f40024-da35-4f34-960d-44d73cad0237/31897702927.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/64cd4556-3200-4c74-9efb-401350ab7340/high_rise_building_construction_safety_checklist.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c1550f6a-541d-4c3b-8fd9-7135bb0566fc/epson_artisan_810_price.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6bf17f54-f25f-40cb-a3b4-77bc042fcee9/how_to_do_1.1_1.2_numbering_in_word_2010.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5b9fac71-d738-46cc-9d66-b0fe94bd5c5f/tikadasi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2ca83b49-e512-4843-935b-a57e8b5cc000/vishnu_sahasranamam_hindi_lyrics.pdfIn PDF document text
- https://7404da97-7fcf-4d5f-9d5f-3f8644e6773a.filesusr.com/ugd/35f767_c23e86aa38a6436f9f08709033097adb.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/8719a5f6-34cd-46c0-a811-11a3ebde5ed6/69624017442.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bdb8a5c1-d9bd-4327-be25-f5289eb62068/juzopulidufefodisivibir.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6747735a-e812-41d8-8c31-69f38eb77514/what_does_local_area_network_mean_in_ict.pdfIn PDF document text
- https://e8677ced-6330-435e-8237-200fb10408a4.filesusr.com/ugd/a4c1fa_fd211b8fb53b4399a7c09c4e8d2a8979.pdf?index=trueIn PDF document text
- https://9177b9cb-4c70-42bd-a9e0-27a1bf53b67b.filesusr.com/ugd/9baf76_9cb5afc15a0b4a2da0a756cad183bc8d.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/8fa595b3-d617-4883-bc90-1f9a02621099/principales_campos_de_aplicacion_de_la_psicologia_industrial.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9e1a048d-66eb-4dcb-b042-5d07b5c00a78/witcher_books_in_order.pdfIn PDF document text
- https://89d37d93-eaf9-4fc7-8d5e-07438b8f18e7.filesusr.com/ugd/e80f4c_a15ae25d2b3340dbbe4a2aca57500858.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/b85ae5ee-b950-4350-8334-972e27c0398c/76988699827.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bd3227f6-e6c5-4032-a417-f14f082019f0/nitemaxotifakikig.pdfIn PDF document text
- https://590703a0-be71-4d3c-a49f-17767d5969ef.filesusr.com/ugd/656c20_3a854f487254420aaf9e92983b6492b7.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f56d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF56D | 5716 bytes |
SHA-256: 6ba841033b0d5bcc6fa38fe45e195d0eb8f4d7f4ecf979b6b6765fedfd8cab28 |
|||
font_01_sfnt_off00010922.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10922 | 11348 bytes |
SHA-256: 3b15ab358236ba766e3af2a3f8d376cd27252a484a4137cef151f792c042fa35 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.