MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The file is a PDF that contains a link farm and is flagged by ClamAV as Pdf.Phishing.Trojan. The heuristic 'SE_ADVANCE_FEE_SCAM_LURE' strongly suggests the document's content is designed to trick users into a scam. The embedded URL points to a domain associated with malicious activity, likely serving as the initial lure for a phishing or advance-fee fraud scheme.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=the+remains+of+the+day+summary+pdf
- https://cdn.sqhk.co/retirijozi/ghBihEy/93029593977.pdf
- https://cdn.sqhk.co/sozivowemin/Ejjjghb/mardi_gras_color_block_shirt_wholesale.pdf
- https://cdn.sqhk.co/lorotukogof/7ZKHiaT/jungle_adventure_free_online_game.pdf
- https://cdn.sqhk.co/tawunipufop/2ghVice/redcon1_mre_bar_canada.pdf
- http://desenusexewu.iblogger.org/84952350110.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/2699c2e7-ee97-4cfa-84eb-e83c8b57eb63/69978377550.pdf
- https://uploads.strikinglycdn.com/files/9684d00f-7235-4105-9648-9f0efd46d6a2/86444297464.pdf
- https://uploads.strikinglycdn.com/files/b854410f-5beb-4d0d-a0cb-2c5f95d6588b/under_the_dome_season_2_episode_1_free_online.pdf
- https://cccd2283-d272-450a-840b-6541230ebad2.filesusr.com/ugd/5de1df_f4ea3d57ba544d8ba6f195502c98461a.pdf?index=true
- https://3edbbcf3-b5b1-446e-9630-835d38fa79e0.filesusr.com/ugd/6908d7_4b2a2ad337994bd2baf2253b6bde9650.pdf?index=true
- https://uploads.strikinglycdn.com/files/c15fda5a-e395-431f-adb2-b945e2ac732b/dell_precision_m4600_launch_date.pdf
- https://8909b315-4d59-4940-aabf-0fdaa532e0ad.filesusr.com/ugd/4542d9_c3c6da1109b447b4964c68facfcd96ce.pdf?index=true
- https://cfecb619-c0f5-418d-ae9d-b1147643389f.filesusr.com/ugd/4cd51e_795d4ddb844d411f8600f537af344007.pdf?index=true
- https://a2214900-82f6-4ed5-a432-d5ffd14110fa.filesusr.com/ugd/306b6b_66844a8ac5394af697de898749488375.pdf?index=true
- https://c63ca81c-6df4-4ec3-bc2e-8508f29a6879.filesusr.com/ugd/d48fe3_0fe936f5bc4c40e994a9e910852bf29e.pdf?index=true
- http://xanojeja.rf.gd/grammar_for_english_language_teachers_download.pdf
- http://fegumipidibig.rf.gd/59915288631.pdf
- https://e8e87dc5-637d-47ba-9de6-e7d98d123d78.filesusr.com/ugd/a69a03_f6afb21b74ab40dfa76c545fa95b4312.pdf?index=true
- https://uploads.strikinglycdn.com/files/02da4803-b82a-4c5e-a76d-67e11286ddf4/programming_comcast_remote_for_tcl_tv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f986.bin2510e1fddfb3e2ee3e983d2f7c2b107bf33ff66bc93e66fa5d71e3434a971d1b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF986 | 5300 bytes |
font_01_sfnt_off00010b66.bin8f4c738882f4c5bae81fe083d467fddf62139d55f450d86a4b93cd2ba6d19d66 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10B66 | 10812 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.