MALICIOUS
212
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of embedded links to external PDF files, a technique often used for SEO manipulation or to host phishing content. One of the links points to a known malicious redirector, and ClamAV detected the file as a phishing trojan. The document body is heavily obfuscated and unreadable, but the presence of numerous links and the ClamAV detection strongly suggest a malicious intent to redirect users to harmful sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.8124
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/strik?utm_term=bunn+coffee+filter+sizes
- https://cdn-cms.f-static.net/uploads/4406501/normal_5fbe0fcc88832.pdf
- https://static.s123-cdn-static.com/uploads/4366321/normal_5fc739c75f4be.pdf
- https://cdn-cms.f-static.net/uploads/4379612/normal_5fa4535f9a27a.pdf
- https://static.s123-cdn-static.com/uploads/4486743/normal_5fdd395f4f6ca.pdf
- https://xigukiburid.weebly.com/uploads/1/3/2/7/132741693/feviw.pdf
- https://cdn-cms.f-static.net/uploads/4385852/normal_5fbddac8680b7.pdf
- https://dejolezeg.weebly.com/uploads/1/3/2/8/132815968/5b679dba22b.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/43b137f8-c685-436f-8ece-075ca73a9238/bushnell_night_vision.pdf
- https://uploads.strikinglycdn.com/files/2fb982dd-0c86-45fe-81a6-db8c63b4a248/48089150135.pdf
- https://uploads.strikinglycdn.com/files/4dca74ff-a52f-4fc9-a507-c095d9d12440/boyd_glass_price_guide.pdf
- https://uploads.strikinglycdn.com/files/b0ca9d7c-e135-4f40-85d5-81aa59d70832/nefiluwebajeg.pdf
- https://uploads.strikinglycdn.com/files/9cc24bea-e8e5-450c-a009-dcfa2afe0e3a/finus.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdf978e18c5c478ec18653/1606285689570/2_room_tents_for_camping.pdf
- https://static1.squarespace.com/static/5fce105bc1e311104da5b134/t/5fd66bdaab1a676c728fc288/1607887834730/xutewij.pdf
- https://static1.squarespace.com/static/5fc0f66f116eb00e3c4c456d/t/5fc8c0254b97230d05146c18/1606991911496/5637162402.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000c900.bin19cd3afbc4cd0a3a0d5a8e49f7a4e67c43c24837f7895c7efe0e76b26092e9a1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC900 | 4764 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.