MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains a mass external link farm, with one prominent URL leading to a "clash of clans hack mod apk download". This suggests a phishing or scam attempt to trick users into downloading potentially malicious software. The ClamAV detection and ML classifier further support its malicious nature.
Machine Learning
- Nyx PDF Classifier malicious score 0.9985
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=clash+of+clans+hack+mod+apk+download+android+1
- https://cdn.sqhk.co/sobupepokor/5sbE4kl/serusuvozagetera.pdf
- https://cdn-cms.f-static.net/uploads/4484804/normal_6056449d60fdf.pdf
- https://static.s123-cdn-static.com/uploads/4421613/normal_5fe2a00b6fff1.pdf
- https://static.s123-cdn-static.com/uploads/4388173/normal_5feb795a98f1e.pdf
- http://mojofaza.mypressonline.com/flowers_in_the_attic_full_movie_free_online.pdf
- http://sirunome.mypressonline.com/que_es_un_lienholder.pdf
- https://static.s123-cdn-static.com/uploads/4446942/normal_5fe1b543be96b.pdf
- https://cdn.sqhk.co/zonakagud/hhdKGCs/jingle_bell_rock_guitar_sheet_music.pdf
- https://cdn-cms.f-static.net/uploads/4481163/normal_6029c51e4e850.pdf
- https://cdn.sqhk.co/jobebakegip/oWHqrka/29638707671.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://ec2d952e-5494-46d8-b841-fee222248b17.filesusr.com/ugd/9713d5_457abd0c68fa4971ba6052ace839d31d.pdf?index=true
- https://4cf6c2b4-cd84-4b73-83b1-bf7f441162b2.filesusr.com/ugd/e50c99_3958051f467e40bb9300ebedb99e675c.pdf?index=true
- https://s3.amazonaws.com/medaliwifufugel/firefox_42._0_offline_installer.pdf
- https://s3.amazonaws.com/tanikanaw/69249354756.pdf
- https://s3.amazonaws.com/tajimipojimo/32277333837.pdf
- https://s3.amazonaws.com/kukazowox/bilaspur_university_admit_card_2018.pdf
- https://s3.amazonaws.com/kulinisokakewi/albeniz_tango_sheet_music.pdf
- https://ff999131-262c-4f46-aa1e-84c50d3d9e43.filesusr.com/ugd/a474dd_b298a88b0586414d8862beb1da3525c1.pdf?index=true
- https://e055bcc9-c4f1-4c6c-8dcb-0912bf54750f.filesusr.com/ugd/b4a829_b1fed82b61294a6186c8ea77657dfe3d.pdf?index=true
- https://s3.amazonaws.com/minabiwa/23833385626.pdf
- https://s3.amazonaws.com/kujapomib/bandhan_film_song_pagalworld.pdf
- https://92923600-264c-4cb8-9d87-181083d4f0d6.filesusr.com/ugd/0bf43f_f759aca291784d3186a0eb6276d33149.pdf?index=true
- https://s3.amazonaws.com/jifesu/lexanilisilefulejis.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://savannah.gnu.org/projects/freefont/
- http://www.gnu.org/licenses/
- http://www.gnu.org/copyleft/gpl.html
- http://scripts.sil.org/OFL
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f0d8.bin3d4760ca295192c89086870ebbac49c5a5945404ea6ab57fca452cf2db5f569a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF0D8 | 6440 bytes |
font_01_sfnt_off000100cc.binca2879bd7ec18bdf8e0fb5f01e6e3306c6bbbd51312579a58bfb6b89b0c0896f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x100CC | 5216 bytes |
font_02_sfnt_off00011262.bina71c52a12841f34db0e1bd61683185916eee8e8df7b780b686e6cc79e29552a4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11262 | 11016 bytes |
font_03_sfnt_off00013806.bin1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13806 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.