MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, specifically flagged as a phishing trojan. It contains numerous embedded URLs, with one prominent URL pointing to 'kuzutuzo.ru' and disguised with a 'utm_term' parameter suggesting a search lure. The PDF's structure and the presence of many links indicate it functions as a link farm, a common tactic for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9954
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=mary+shelley+frankenstein+film+2018
- https://cdn.sqhk.co/furafurume/7865Gq6/alone_lyrics_alan_walker_ft_ava_max.pdf
- http://goodxday.xyz/watolajodajifuxidabixuful6xp.pdf
- http://ryursew.space/447282890279pkfk.pdf
- https://cdn.sqhk.co/xekobigi/cUjfFQ7/calculus_1_worksheet_7.pdf
- http://rentline.pro/reweferoxuvobiminawijapiinm.pdf
- https://surugatolezijef.weebly.com/uploads/1/3/4/6/134631687/gawim_zukonuxenape_kinuriv.pdf
- https://zumizosapozogem.weebly.com/uploads/1/3/2/6/132681504/kirirekodeluxisa.pdf
- http://agent-ritual495.online/can_you_call_your_child_god_ukfjo1n.pdf
- http://momentshop.website/50525605545fgdry.pdf
- https://cdn.sqhk.co/disumuneriva/dhKjdAX/zumavujawopukurowo.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://bef89f6e-6323-4b84-ad9d-a44490bfcc4f.filesusr.com/ugd/96768c_504a53356c7e45f1a2fbc497fc4643cd.pdf?index=true
- https://0feddc0e-03bc-46a3-a741-45303deff239.filesusr.com/ugd/6ea6a2_e1d0f6af7901426ea0aa5ee7dd3cdbb7.pdf?index=true
- https://3f46bf15-0a8c-4e80-b3e5-a2e3bf90e008.filesusr.com/ugd/8e6e76_3c22ee718a2d4e59891a4b0b78d03dfa.pdf?index=true
- https://4779f2f8-a33e-4327-9c78-21ee0bcf4620.filesusr.com/ugd/31bf02_028a9e3e6fa04b0fb619a3e8b833552f.pdf?index=true
- https://709e7e89-b264-4d73-b757-064736ed86f1.filesusr.com/ugd/f523c3_19c71f2660504d53b407136671119d59.pdf?index=true
- https://5a4e7950-e122-4b3c-9cf7-894e7f5b1216.filesusr.com/ugd/76aeb6_30abd7e9ba8240e68a6ef69c9d94a621.pdf?index=true
- https://121f8fc1-d270-4171-a721-8ccd656fc20f.filesusr.com/ugd/2ca22b_cb1e479532d546b2835d8bcd127d5843.pdf?index=true
- https://a2fe464c-28d1-4db8-bb2d-552ad9bc2f4d.filesusr.com/ugd/941bb1_46aa6d8f997e4b87a8f04a749a23ab96.pdf?index=true
- https://1e16f6d7-285b-4488-bf07-d3e24ac90e20.filesusr.com/ugd/417718_a79ce4afcef1424b9bafc78221ba302c.pdf?index=true
- https://7fc1e5b2-1dd8-4457-9de2-3dea1ab9f589.filesusr.com/ugd/fedd61_7628f2cfc3fa455d9cba9dc76f9d9f2f.pdf?index=true
- https://2a085669-a8dc-40eb-b1d3-71ea9d660f60.filesusr.com/ugd/cafc24_de9af32609324b788ba0c5765b8ce1c5.pdf?index=true
- https://87164119-88a6-4d6d-a72f-b109cf2d88b9.filesusr.com/ugd/bd0a66_55df9884d76f425f900ce28a4295c491.pdf?index=true
- https://2a497570-3881-454f-aefc-229a18bbdf22.filesusr.com/ugd/83e24f_6d0f06fa47d74bd4ad0f8eeec9771708.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000287ae.binf358ef12190eb98c3cee1d571aa7d00cdc237fe80b5a60473174f79ab363adae |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x287AE | 5696 bytes |
font_01_sfnt_off00029afb.bin4b9f28cf80113ab99445028a58d22939492bcc0e748d3722f5400926ae8ff231 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x29AFB | 16424 bytes |
font_02_sfnt_off0002cc21.bin7e40d5abf1f05989346ccbec6620ecff522e3627ebf02262ce8db76c6a4f6d01 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2CC21 | 17160 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.