MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9956
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://baarspo.ru/123?utm_term=automatic+call+recorder+pro+free++app PDF link annotation
- https://cdn-cms.f-static.net/uploads/4459177/normal_606c47939f39a.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4370530/normal_6037c3270e90a.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4412902/normal_5ff3c1d0c1f80.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4411229/normal_5fcc82cc6fdf6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4446636/normal_6055c122015ed.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4497369/normal_601241de57a5a.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4501659/normal_6027b6cc4d143.pdfIn PDF document text
- https://pewoguliburutoj.weebly.com/uploads/1/3/4/2/134234653/medaxowogetoj.pdfIn PDF document text
- https://kaxobemux.weebly.com/uploads/1/3/4/6/134676595/1c44b06.pdfIn PDF document text
- https://folumenudi.weebly.com/uploads/1/3/2/6/132681426/mafite.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4450248/normal_601db529a2355.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4460723/normal_5ff2acc0876f8.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4451374/normal_604e1710285fc.pdfIn PDF document text
- https://gitujibexilen.weebly.com/uploads/1/3/1/4/131406430/4759691.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/444ecf88-8ac1-499d-8c8e-3f0b47ced60c/zurupipoxobol.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b603d781-2be6-40b9-8edb-47ad0fda8105/50786168234.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6ff7a0bd-4335-4ddf-ae1a-e8f4e4bbc9e8/11528503019.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b263ed87-ff2f-49b7-95c2-53eefc4f9334/54557740164.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/add74324-a028-4d13-8fb9-9e519e60a5d8/ralufamoxugimer.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3aed3885-d89f-42de-a363-94c45cfe75ef/how_to_put_a_toro_zero_turn_mower_in_neutral.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/590820a1-408b-4103-92d1-c6bf337665ce/sowakojikijawaxunos.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/78db28cc-d50f-450b-8220-4f6f1bf641cf/86586055570.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f0447870-038d-45e0-b103-dcbaaaf1ad13/retevujuzokuwesotojixotu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2ad6ea99-db16-4d48-97ce-89708b61696b/xepefofesak.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3002ddc8-a316-4523-baa7-39f3f7285b15/53891508888.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ba1cbe77-2408-42d4-85ab-80a82002a709/how_to_assemble_a_spalding_portable_basketball_hoop.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e663.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE663 | 5112 bytes |
SHA-256: 56d43cb0e92c8b966764256a8efad56f326a7666a69b8957968fd151a0316e19 |
|||
font_01_sfnt_off0000f7af.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF7AF | 21972 bytes |
SHA-256: fc261fb16bf5040492548cc1682965181ee97c8650eebd3c4d74d3cf4a0681b5 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.