MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file was detected as malicious by ClamAV and an ML classifier, with high confidence. Heuristics indicate it contains a link farm and an advance-fee scam lure, suggesting the document's purpose is to trick users into visiting malicious links for fraudulent purposes. The primary malicious URL identified is ponafet.ru.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/strik?utm_term=resumen+del+libro+ficciones+de+jorge+luis+borges
- http://richteam.site/90336831227hiyc9.pdf
- http://ledimpress.biz/45182783478hxyri.pdf
- http://mkuu.club/47863248753uxfap.pdf
- http://yandex-delivery.cc/what_is_the_less_normal_more_on_instant_pot7ndbf.pdf
- http://nutristrike-shop.ru/how_to_make_base_in_dayz3vu2m.pdf
- http://strapslap.online/precalculus_textbook_mcgraw_hill30xfy.pdf
- http://thelait.pro/college_prep_algebra_2e_workbook_answersdekcw.pdf
- http://strita.space/wukojudiwfxjeb.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/5688092c-fc1a-4890-854f-e6262ca57632/rutugariwozekezaw.pdf
- http://nizalag.rf.gd/email_id_validation_regular_expression_in_android.pdf
- http://kixeret.rf.gd/bdlaws_gov_bd_part.pdf
- http://molagisonapem.epizy.com/24609079993.pdf
- https://uploads.strikinglycdn.com/files/96395be9-0e90-40e4-8c39-a2f1f0d0f5da/mijuvevelevodonerotu.pdf
- https://1ffb5d6c-d890-49e0-9b87-dc10fbfa49e2.filesusr.com/ugd/8bc2a6_58b2c5596e494eb4a154d645ddfc35a6.pdf?index=true
- https://uploads.strikinglycdn.com/files/c5502c24-ff1d-48bd-b456-18fb85f83730/77719653715.pdf
- http://bilumolekotejoj.rf.gd/mortal_instruments_casting_director.pdf
- https://6cbe2f5c-748b-4bc6-b691-25a968a47885.filesusr.com/ugd/d6b5da_aea6f5d457234914ace6f9e4447a0fc5.pdf?index=true
- https://uploads.strikinglycdn.com/files/abcd19c0-0080-486b-8bbc-903bb7890216/dijekeminag.pdf
- https://uploads.strikinglycdn.com/files/d2341d32-5243-4b1a-b981-7070c0f17364/into_the_woods_script_musical.pdf
- https://uploads.strikinglycdn.com/files/c842871e-1f88-4805-a6e7-7c7dfba61774/roguxawonubavofok.pdf
- https://uploads.strikinglycdn.com/files/1fab2626-bd19-40a8-af7d-5d1abcba68c0/80107057927.pdf
- https://uploads.strikinglycdn.com/files/383fc393-bb25-4135-b2d2-046c26d01eca/70885645238.pdf
- http://zidumive.rf.gd/26925304517.pdf
- https://uploads.strikinglycdn.com/files/18f4ec0b-34ac-4970-8469-69980f4dfcb4/95285449608.pdf
- https://9170d309-caca-4186-8987-bf6b40ce219c.filesusr.com/ugd/baef12_ccc7580f5a454cff869c106b6baffb57.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011311.bin3059810c201c673b51e5c2651db53c446823db30fc430caeb4ccc81b6e9dc695 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11311 | 5356 bytes |
font_01_sfnt_off0001253a.bind99c4128e1fd0a34a48e2a62845d606fca95b4fcc19e0cdfd80fc0a96ad7ec66 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1253A | 11956 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.