MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file, identified as malicious by ClamAV and an ML classifier, contains numerous external links, suggesting it is part of a link farm or phishing campaign. The document body, though heavily obfuscated, contains references to 'Star wars outbound flight canon' and 'wkhtmltopdf', indicating a lure to attract users to potentially malicious websites. The presence of multiple external URIs and the 'PDF_SEO_LINK_FARM' heuristic strongly suggest the document's purpose is to redirect users to other sites, likely for malicious purposes.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafffi.ru/123?utm_term=star+wars+outbound+flight+canon
- https://cdn-cms.f-static.net/uploads/4367300/normal_5fa72310075b7.pdf
- https://dodivimibo.weebly.com/uploads/1/3/4/3/134305777/fafozabog-lubuvenonozamu-nukuwuboxavi-tejisewa.pdf
- https://cdn-cms.f-static.net/uploads/4464083/normal_5fadd649b89f8.pdf
- https://firedisivimi.weebly.com/uploads/1/3/0/9/130969818/968470.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/c839cef3-ddd6-4e65-a13d-10a81bafba77/78897820932.pdf
- https://uploads.strikinglycdn.com/files/2996a6aa-5429-41f9-a9d1-49373d8aa3fa/kinutipowixaweninarudo.pdf
- https://uploads.strikinglycdn.com/files/7fa3c78b-77dd-4841-9e87-52dd92c1d6da/delivered_from_the_power_of_darkness_emmanuel_eni.pdf
- https://uploads.strikinglycdn.com/files/a882170b-4c0d-48de-b31a-b27b5cea2e14/32436078826.pdf
- https://uploads.strikinglycdn.com/files/6379346f-57c9-41ec-85c2-0e2b2eb969b1/kofusonebuzigasuvotoduxaz.pdf
- https://uploads.strikinglycdn.com/files/892a7856-cdee-4191-a2b6-daa702da29a7/50491206126.pdf
- https://uploads.strikinglycdn.com/files/0d392114-4711-4334-9526-0fcafc44cc75/93411345791.pdf
- https://uploads.strikinglycdn.com/files/630944e6-0ef4-4afc-b002-cdfcc873b0be/40065106087.pdf
- https://uploads.strikinglycdn.com/files/5ee95db6-2d3e-4892-ab0b-95ccd5ae73cf/kimumobav.pdf
- https://uploads.strikinglycdn.com/files/56b6e02d-9f77-4f5d-bbba-21b28c1eb194/y8_games_slither_oi.pdf
- https://uploads.strikinglycdn.com/files/2e192c9c-bb24-4890-a5a9-b95577cccf99/wewozatapofobuxux.pdf
- https://uploads.strikinglycdn.com/files/d245e378-c0d5-4d58-ac27-f75fb7711904/aeg_favorit_dishwasher_manual_f34300v10.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00014f4d.bineb46d25d492747433bf798740aeeb9e2cb925e17b6c4e63963accbf792c42e2d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14F4D | 5616 bytes |
font_01_sfnt_off00016277.bin311108ed03da2c6889b5bffc598cee4cec4c85fed5ebd1335b33525d361d1ec8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16277 | 12428 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.