MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with a critical heuristic firing for PDF_SEO_LINK_FARM indicating a mass link farm. One specific link, http://lenumizisil.rf.gd/mary_poppins_lyrics_supercalifragilisticexpialidocious_backwards.pdf, is flagged as a random URL. The ML classifier and ClamAV detection strongly suggest malicious intent, likely related to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINKPDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/wix?keyword=grupos+financieros+de+guatemala
- http://vonurejawata.iblogger.org/lg_electronics_tone_pro_hbs-750_bluetooth_wireless_stereo_headset.pdf
- https://cdn-cms.f-static.net/uploads/4391326/normal_602eda4bd7005.pdf
- https://babikovinemixe.weebly.com/uploads/1/3/1/8/131856339/woxopidevugefij.pdf
- http://fikizabeji.22web.org/56543008368.pdf
- http://gedirobidepud.scienceontheweb.net/71701108276.pdf
- https://cdn-cms.f-static.net/uploads/4424029/normal_603943051d342.pdf
- http://verunej.iblogger.org/thoreau_quote_walk_in_the_woods.pdf
- https://nefupoxuwuridek.weebly.com/uploads/1/3/4/7/134747690/losuv.pdf
- https://fulojexerewo.weebly.com/uploads/1/3/5/3/135345176/jinageze.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://7ae774ad-b64d-4473-a0b1-aa0db1e39e83.filesusr.com/ugd/3e7897_c1e2e42525dd4d72be4b660c9eecd17b.pdf?index=true
- https://3c45aaf8-24f3-4cde-9773-cf44a0a970d3.filesusr.com/ugd/ae7d54_9ff571bb26d940ea9e11d2cbfedb9410.pdf?index=true
- http://vujapaporetakik.epizy.com/reproduccion_de_las_angiospermas.pdf
- http://wiwosotu.myartsonline.com/who_moved_my_cheese_overview.pdf
- http://lenumizisil.rf.gd/mary_poppins_lyrics_supercalifragilisticexpialidocious_backwards.pdf
- https://51da6a7d-ee05-4a49-87ee-1b74af3aeb07.filesusr.com/ugd/b80405_6fff25fea089486185068a3bb0f7ab35.pdf?index=true
- https://c3438639-6a75-4920-aa4f-d1e0b619354f.filesusr.com/ugd/3be3a7_8d5056bd05574b06b71cb9abdf49563d.pdf?index=true
- http://wisituvoj.epizy.com/is_python_a_good_coding_language_to_learn.pdf
- https://656adf98-7a81-40bd-8d0f-2b9c27d09201.filesusr.com/ugd/268ab1_4d8ff86ee6de4249905adfe83b9b15e4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e25c.bincd5cec0c0028d9d2c6a3f5be5db13d18b5abbc709ad40437a3671b9f8273f221 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE25C | 5508 bytes |
font_01_sfnt_off0000f504.binf0ac767805b7bca57db0d17449675bd644cbc8ddf382e8ff967c7cfbec36ca85 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF504 | 11604 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.