MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, characteristic of a link farm or SEO spam, designed to direct users to potentially malicious websites. The document body, though heavily obfuscated, suggests a lure related to PDF to Word conversion, a common tactic for phishing or malware delivery. The ML classifier also flagged this PDF as malicious, reinforcing the suspicious nature of the embedded links and overall document structure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9571
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/award?keyword=pasar+de+pdf+a+word+ilovepdf
- https://cdn.sqhk.co/xuzalolotagi/cigljem/volenibodubap.pdf
- https://cdn.sqhk.co/binuwaxe/k2jgh4K/zederilel.pdf
- http://kiritisivasol.mywebcommunity.org/16031168501.pdf
- https://cdn.sqhk.co/nozelenid/g51ewLa/squarehome_key_launcher_windows_style.pdf
- https://cdn.sqhk.co/gatutojuse/PjjbyXI/venedabo.pdf
- http://xunopapazugatar.medianewsonline.com/tufuveduwaninet.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://vedumojaje.epizy.com/lexemobenojofov.pdf
- https://21d44941-995c-48b9-956b-8145330e20d5.filesusr.com/ugd/577b75_65e677656b8749ef8d324b924a4b2c36.pdf?index=true
- https://s3.amazonaws.com/wenobagupexekap/63769330421.pdf
- http://sazitoza.epizy.com/nexudixumemijonuw.pdf
- https://s3.amazonaws.com/posufij/how_to_make_custom_actionbar_in_android.pdf
- https://s3.amazonaws.com/babuxufarizuxur/bollywood_movies_top_10_websites.pdf
- http://roduzafudi.rf.gd/25913299024.pdf
- https://s3.amazonaws.com/votubukaxogilix/56784181167.pdf
- https://a4758657-6aaa-4003-b0f6-1957e800abfd.filesusr.com/ugd/70c1f8_6f2819bd92dd4399ba3d38c40abbf449.pdf?index=true
- http://xuwanozofugis.epizy.com/sobuw.pdf
- https://s3.amazonaws.com/tufitijinexu/16884550016.pdf
- https://e3055f73-6236-423b-b810-4bc1a15f300f.filesusr.com/ugd/fa12d1_aa72d5f6823e4b80b920e0c6937b6834.pdf?index=true
- http://tefotesibeto.epizy.com/rurudobi.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d699.bin5d8e986425877760fb942ae751f0bee8baffcba06d71c2b034410f714af8b35b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD699 | 5188 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.