MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, many pointing to Weebly-hosted PDFs, suggesting a link farm or SEO poisoning tactic. The primary URL, 'https://lozipotod.ru/wix?keyword=statement+of+purpose+mechanical+engineering+internship', indicates a lure related to academic or professional applications. ClamAV and ML classifiers strongly indicate malicious intent, likely phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/wix?keyword=statement+of+purpose+mechanical+engineering+internship
- https://jonurimexiv.weebly.com/uploads/1/3/4/3/134321783/7185400.pdf
- https://cdn-cms.f-static.net/uploads/4377379/normal_5fd627d705b8a.pdf
- https://mujekakuvegaxum.weebly.com/uploads/1/3/2/3/132303245/8644694.pdf
- https://wavenugila.weebly.com/uploads/1/3/4/8/134852162/1861718.pdf
- https://cdn-cms.f-static.net/uploads/4428052/normal_602afa8062976.pdf
- https://pupalizote.weebly.com/uploads/1/3/4/7/134716330/moguxatixaf.pdf
- https://dojilosadokadog.weebly.com/uploads/1/3/4/8/134890500/f42dab04.pdf
- https://zutiwijutorezaz.weebly.com/uploads/1/3/4/3/134354078/6501798.pdf
- https://vefonero.weebly.com/uploads/1/3/1/0/131070196/7688980.pdf
- http://storedubai.shop/difference_between_general_purpose_specific_purpose_and_central_ideabuv3p.pdf
- http://tegor.xyz/joycon_droid_amiibo_files80ovl.pdf
- http://frontend-developer-azaynullin.site/bukupazurefuvimirawonwwl8.pdf
- http://fly-drive.online/outbreak_meaning_covid5s7pw.pdf
- https://static.s123-cdn-static.com/uploads/4374696/normal_5fe0c67c791f6.pdf
- https://valuzobuxile.weebly.com/uploads/1/3/2/7/132711949/jinofipibakuzot.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://0dd4521b-3e41-4083-9bcc-807cce03ae78.filesusr.com/ugd/cfe2e9_99b7a33905ea42519999f8280910955b.pdf?index=true
- https://s3.amazonaws.com/foneniz/heart_touching_sad_life_quotes_in_hindi_with_images.pdf
- https://34e2f0dc-0077-42bd-a047-efa2502e92af.filesusr.com/ugd/8a05ec_a27625ab3c88463ba1cd147fce931c61.pdf?index=true
- https://f8b2de7a-6012-4721-b8f1-df5267d6bb95.filesusr.com/ugd/8ebb60_d574a752461c4412bbe52d930966e38b.pdf?index=true
- https://s3.amazonaws.com/nuxepiduded/arcsoft_totalmedia_3._5_serial_key.pdf
- https://a62e46b8-d933-4087-892c-e5439cec6991.filesusr.com/ugd/e9cba9_490b6c58143a41178d8e9177da3bc7dd.pdf?index=true
- https://36425c1f-c329-48aa-845d-1f8252cb45c8.filesusr.com/ugd/01d500_101ac9a553634571a99bafc423a60060.pdf?index=true
- https://s3.amazonaws.com/vosimalume/59502890884.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fa1c.bin3c304c5c227548d85af0436a16fcd6e995469a777a498531b6faf88a3802c9ca |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA1C | 5532 bytes |
font_01_sfnt_off00010cc9.bin99025e2f94eec44f2e19f2b6a4f581ef43b48143f34b8f957c570eca49c41dec |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10CC9 | 11132 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.