MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with a critical heuristic flagging it as a 'PDF_SEO_LINK_FARM' designed to host a mass of external links. One of these links, 'https://maypoin.ru/wix?keyword=runescape+free+to+play+ironman+guide', is embedded in the document body, suggesting a lure to a malicious site. ClamAV also detected this file as 'Pdf.Phishing.Trojan'. The presence of embedded URLs and the link farm heuristic strongly indicate a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/wix?keyword=runescape+free+to+play+ironman+guide
- https://cdn.sqhk.co/vafegijateno/bagdCVx/30523207352.pdf
- http://mirror-x.org/fexixevmtbzl.pdf
- http://1xbet-regi.site/52623686238e569h.pdf
- https://ratamugokamilel.weebly.com/uploads/1/3/5/9/135959592/jopasu_zevokufujodux_mubewakepota_buzavujowamu.pdf
- https://xezatitewifesel.weebly.com/uploads/1/3/4/3/134393938/tenizidezikuguzizil.pdf
- https://nelejejo.weebly.com/uploads/1/3/4/8/134883178/24521cbce671.pdf
- https://cdn.sqhk.co/lewemimi/iahiPJl/instagram_search_account_name.pdf
- https://cdn.sqhk.co/pirasemofoge/Whbggj7/22940215310.pdf
- https://cdn.sqhk.co/jegamaxegev/77GNihS/game_of_sultans_viziers_best.pdf
- http://bitcoinlearningcentre.online/69967897827o91vv.pdf
- https://wuriwodek.weebly.com/uploads/1/3/4/6/134688082/fujolos-lumezebiji.pdf
- https://lidovoji.weebly.com/uploads/1/3/4/3/134313359/44297770d59f1c.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/posaxugidut/68909502490.pdf
- https://uploads.strikinglycdn.com/files/42a3607c-9d1c-4759-aa8b-705966ec4313/moremuxifebukuzina.pdf
- https://s3.amazonaws.com/zuwosil/39614706585.pdf
- https://s3.amazonaws.com/dotivaf/42018772693.pdf
- https://s3.amazonaws.com/gewuwasi/tag_template_kendo_multiselect.pdf
- https://uploads.strikinglycdn.com/files/03325dbd-f978-4306-83ff-99719f43d1f8/zitakafaruviwovazinaxireb.pdf
- https://uploads.strikinglycdn.com/files/ea995925-832f-43c1-816f-167db2eb2e9f/family_feud_game_online_zoom.pdf
- https://uploads.strikinglycdn.com/files/e975c30b-d3cd-4e4e-8828-09aba602d49a/dowubavefubosupupimef.pdf
- https://s3.amazonaws.com/jivuxo/58993662585.pdf
- https://uploads.strikinglycdn.com/files/42024206-ff55-4518-9fc6-54dc81b37b25/gor_books_by_john_norman.pdf
- https://s3.amazonaws.com/kewuxejikiwe/linguisystems_guide_to_communication_milestones.pdf
- https://s3.amazonaws.com/zuwimadaneb/lureroxagigedi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00015dbe.bin6f8132d0041fd4415bb56043ec74423849ae1c046294a5aeaca9ef3bf87b6bcd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15DBE | 5584 bytes |
font_01_sfnt_off000170b8.bin979389771bdaf829a537745116bb1eeeb71fd717dcb89ba277b291ed808bad54 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x170B8 | 11072 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.