MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains a large number of external links, many pointing to potentially malicious domains, suggesting a link farm or redirection scheme. The document body, though heavily obfuscated, contains metadata related to 'wkhtmltopdf' and a title that might be a lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffine.ru/123?utm_term=katsute+kami+datta+kemono-tachi+e+rating
- https://kogemujifogez.weebly.com/uploads/1/3/4/3/134344524/jarovaso.pdf
- https://rajivuwos.weebly.com/uploads/1/3/4/3/134398668/8d84947fd52fb17.pdf
- https://cdn-cms.f-static.net/uploads/4369657/normal_5f882a785d82d.pdf
- https://pasuzexogisinib.weebly.com/uploads/1/3/4/2/134266431/9838498.pdf
- https://solubowobadiwu.weebly.com/uploads/1/3/4/6/134642134/nisujipoteg-lirenaxiwanini-mifora-tifurenapo.pdf
- https://ramipataxeki.weebly.com/uploads/1/3/4/4/134483057/6509543.pdf
- https://cdn-cms.f-static.net/uploads/4368471/normal_5fadd880b4add.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/44fd2e47-6fb8-40d7-b72c-b37dab85b80c/bfs_and_dfs_time_complexity.pdf
- https://uploads.strikinglycdn.com/files/7ffcc6b9-5afa-4cd4-bb2e-519e7a61d6bf/65153193403.pdf
- https://uploads.strikinglycdn.com/files/3b39642f-3ea2-448c-8ac5-7dd099775066/72118873216.pdf
- https://uploads.strikinglycdn.com/files/fb31a61c-a40e-4bf2-9ab2-cd88731ff266/97434001596.pdf
- https://uploads.strikinglycdn.com/files/d0aa95a6-9082-4fb9-bc17-a52790195a59/gejefudomelubuvepubirimu.pdf
- https://uploads.strikinglycdn.com/files/40f0553a-2761-4051-bb62-6b7fa00b0464/binder_clip_catapult.pdf
- https://uploads.strikinglycdn.com/files/6c0171ba-29b1-41ed-a882-d404112892b3/ruzagukal.pdf
- https://uploads.strikinglycdn.com/files/26ab1cf2-8372-416c-ab7a-86a178808fef/3_quarks_daily_wikipedia.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010607.bin3d25022bfb5c6ea9946265cb722731d36f8d713c14af05c3072f799b537a5daf |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10607 | 7616 bytes |
font_01_sfnt_off00011f05.bin55eb3a9b3f7cc8f6e483646c49ff09e26a8cb384a3d0c87de49c31d0aa6338d2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11F05 | 5388 bytes |
font_02_sfnt_off0001312f.bin1cb7ba2391548574aa4174401d46f04c1ecd8de7109d37a248a132b32a2934d5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1312F | 12072 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.