MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, a common tactic for link farms or phishing lures. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically identified as a phishing trojan. The presence of embedded URLs and the PDF_SEO_LINK_FARM heuristic suggest the primary goal is to redirect users to potentially harmful websites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/wix?keyword=classroom+observation+form+for+students
- https://kumajevebak.weebly.com/uploads/1/3/1/8/131856027/rinikusipe.pdf
- http://tijudozi.scienceontheweb.net/bagifojowemapa.pdf
- http://housefashion.ru/my_car_runs_lean_at_idlezn10j.pdf
- https://cdn.sqhk.co/xurunesijud/higgyie/rotator_cuff_pain_location.pdf
- http://crawlmqyu.space/952323261624atat.pdf
- http://car-test.pro/residoxosajifamenixalejtvyf.pdf
- https://zejanedigerexig.weebly.com/uploads/1/3/4/7/134757062/peribowotixize.pdf
- https://fogasofimoxor.weebly.com/uploads/1/3/1/0/131071298/3724783.pdf
- http://losqutoq.online/filing_a_police_report_online_las_vegas9uo4t.pdf
- http://itanah.space/australian_masters_rowing_championships_2019_results8k8qs.pdf
- https://cdn.sqhk.co/pixazizaze/hhZjhhf/pozedesejazuvevero.pdf
- https://vokefepafox.weebly.com/uploads/1/3/4/3/134333292/sujuno.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/72c809b2-c1b3-4f84-b51b-c24274fe0a14/96872437944.pdf
- https://uploads.strikinglycdn.com/files/79619bd1-41cc-42fd-81f2-23a93575b38a/punujis.pdf
- https://uploads.strikinglycdn.com/files/36386dbe-0b01-4ad8-bdad-99783d786450/bulovugakap.pdf
- https://uploads.strikinglycdn.com/files/6cb8a7b7-7844-4c91-bcf3-436cf1245ae2/power_pressure_cooker_xl_instrukcja_obsugi_po_polsku.pdf
- https://uploads.strikinglycdn.com/files/0080b221-c669-4b6c-84c0-b4b4b73b2700/jokewabapibubanonovolamif.pdf
- http://kifesafijupesob.onlinewebshop.net/every_mans_battle_book_summary.pdf
- http://jisunopesaluzi.atwebpages.com/what_is_lean_in_agile_methodology.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010a8d.bina142c821b39857b0cf6973b20c47963b6b234de36100dbfcb71cd86b89df1564 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10A8D | 5160 bytes |
font_01_sfnt_off00011c04.binf6868b0032e38bdeb2125c79e17177002d0c0e7afd420fd1fc8cb3bce18ab745 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11C04 | 11044 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.