MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, suggesting it functions as a link farm for SEO manipulation, likely directing users to malicious websites. The primary malicious URLs identified are 'https://nipisod.ru/wix?keyword=nosotros+no+jose+bernardo+adolph+in+english' and 'http://zuzorovix.scienceontheweb.net/jizovirebaposiko.pdf'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/wix?keyword=nosotros+no+jose+bernardo+adolph+in+english
- http://zuzorovix.scienceontheweb.net/jizovirebaposiko.pdf
- https://sewetupowak.weebly.com/uploads/1/3/5/9/135971958/75020b9b.pdf
- http://bejisosubonito.sportsontheweb.net/ernhrungsplan_ketogene_dit.pdf
- https://static.s123-cdn-static.com/uploads/4444386/normal_5fc6b82f4f65f.pdf
- https://roserilufelojow.weebly.com/uploads/1/3/1/8/131856860/5731521.pdf
- https://cdn-cms.f-static.net/uploads/4391314/normal_5fdc5a31c908a.pdf
- http://fexevewuli.mypressonline.com/bagewowivirafibibegurafag.pdf
- http://sollabs.xyz/60996253424zdvwe.pdf
- https://momobalujinas.weebly.com/uploads/1/3/2/3/132303205/5e2116d974.pdf
- https://kebonipima.weebly.com/uploads/1/3/0/7/130740513/9836977.pdf
- https://static.s123-cdn-static.com/uploads/4428062/normal_5fc73ee06dbd0.pdf
- http://velesvoyage.ru/equation_differentielle_a_variable_separable_exercices_corrigs96c9p.pdf
- http://reduslim-ordina.site/vw_service_garage_cardiff2kbo7.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/d211284b-e5a4-4336-8b57-ed87b3aafa9d/tufagalutotuva.pdf
- https://uploads.strikinglycdn.com/files/eeb65b83-9d1b-4a31-ba77-83a19ad58192/mikugivokadefabu.pdf
- https://uploads.strikinglycdn.com/files/c65d0575-99c1-419d-b060-26f6307d7386/sapugodemogot.pdf
- https://uploads.strikinglycdn.com/files/460e63eb-b941-4326-8678-bc0a1a7fdba0/tesla_model_3_performance_0-60_test.pdf
- https://uploads.strikinglycdn.com/files/eef5db96-d482-4cbb-905b-0a5447f0df90/55896919669.pdf
- https://ed21222e-fee3-4fab-8b52-e2ddb7bb35ab.filesusr.com/ugd/e73fea_eb25131b68524f80a4f959c377bf6f0c.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000daf7.bin10a07fc969e6c8cf41398fcfefa625e426b29a45b33f3716d0886db1405c0d2a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDAF7 | 2900 bytes |
font_01_sfnt_off0000e53a.binb2aff1b45639a455d505ead47c23b047736c6539cb6943dfd0a52b2e01251a28 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE53A | 5408 bytes |
font_02_sfnt_off0000f798.bin57c9dd85d77e5dde245f2ad7d808708ceb84c725d828e2f6246f14c94b6ed610 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF798 | 12100 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.