MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF was flagged by ClamAV as a phishing trojan and ML classifier indicated high maliciousness. It contains a large number of external links, many pointing to S3 buckets and other domains, suggesting a link farm or SEO manipulation tactic. One of the external links, https://vilenefex.ru/wix?keyword=600+bce+to+1450+ce+timeline, is directly referenced in the heuristics, indicating a potential lure or content delivery mechanism.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/wix?keyword=600+bce+to+1450+ce+timeline
- http://keepsufi.space/do_nike_employees_get_discount_on_apple_watchsuhmt.pdf
- http://akb54.ru/livre_guide_de_la_route_20197i82c.pdf
- http://shtangelkipokupkiitd.online/kudejifutoseje2e8m.pdf
- http://plafond.xyz/73904455698g9stg.pdf
- http://plusstore.pro/655492833543gf3b.pdf
- http://helplnstagramcontact6088756.com/fakodt8g6d.pdf
- http://kersita.fun/19305503508okwjx.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/bolovopizonuki/dusuxugowoba.pdf
- https://s3.amazonaws.com/gomakobez/past_papers_question_bank_sat_subject_test_math_level_2.pdf
- https://38f9ccf9-db33-4582-994d-0ea518e52d38.filesusr.com/ugd/368de4_14470a2567f147d0b24c7c8eb388caa1.pdf?index=true
- https://s3.amazonaws.com/tigewibejageju/r12_to_r134a_conversion_kit_walmart.pdf
- https://s3.amazonaws.com/ninasivol/8286076751.pdf
- https://s3.amazonaws.com/rovuweraja/why_is_my_whirlpool_side_by_side_not_making_ice.pdf
- https://c36efdde-2309-4ce2-a10d-b6df2ce12cd8.filesusr.com/ugd/e98059_0bdb7f39e0f24377bf2e368af0217f3f.pdf?index=true
- https://s3.amazonaws.com/tokatefozude/96616334864.pdf
- https://s3.amazonaws.com/litunux/adobe_illustrator_templates_free_s.pdf
- https://s3.amazonaws.com/fazujo/kawogixaw.pdf
- https://s3.amazonaws.com/padadutiseni/android_floating_action_button_image_size.pdf
- https://s3.amazonaws.com/jadudusujuje/octopus_pro_apk_indir.pdf
- https://s3.amazonaws.com/baxekojojexusol/australian_citizenship_test_questions_and_answers_2018.pdf
- https://s3.amazonaws.com/vabedafozo/gefafowujovokazek.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f8e4.bine909d2d0b6184eab2b1e2633f1560aae0571cedfc559aa54c98f88a06e5af416 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF8E4 | 5068 bytes |
font_01_sfnt_off00010a2a.bin594684f87b5f69d1c5bd20552f9e17f2277b96cba3253282ddc6ad19535f1f20 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10A2A | 11344 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.