MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains a large number of external links, suggesting a link farm or SEO poisoning tactic to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, and the 'SE_PASSWORD_ARCHIVE_LURE' suggests a common method for evading gateway security by encrypting payloads. No scripts were extracted from this sample, but the extensive linking behavior points towards a downloader or redirector role.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/award?keyword=netis+wf2780+manual+pdf
- https://cdn.sqhk.co/rugofufol/Hjbqhjn/commuters_sans_font_download.pdf
- https://jafobepajimo.weebly.com/uploads/1/3/4/8/134881918/5856169.pdf
- https://cdn.sqhk.co/kevekelobivo/jT0umak/tamil_to_english_dictionary.pdf
- https://cdn.sqhk.co/delojiwuguj/ggZXlvW/aerox_2020_white_price.pdf
- https://cdn.sqhk.co/kekoseni/b6wvmgh/octopus_watch_v2_uk.pdf
- https://wisenuru.weebly.com/uploads/1/3/1/8/131856959/7614188.pdf
- https://bazifimu.weebly.com/uploads/1/3/4/6/134661545/35568e.pdf
- https://cdn.sqhk.co/zuzipogowita/wIiajji/fab_mobile_banking.pdf
- https://cdn.sqhk.co/sebixodof/2fXcSMQ/drawing_railway_tracks.pdf
- https://cdn.sqhk.co/xeposetuge/cgelig5/95329910753.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://bogadamarixufa.epizy.com/kenmore_front_load_washer_error_code_te.pdf
- https://uploads.strikinglycdn.com/files/33f2851d-c247-41a5-8a19-913dc5bff3c2/husqvarna_440_reviews.pdf
- https://uploads.strikinglycdn.com/files/a4fb1164-9ecb-4aff-b8e0-72ecb19c253a/5410857580.pdf
- https://uploads.strikinglycdn.com/files/3ad8b433-eadf-4a82-9c3d-8851943a113d/what_is_statistical_learning_theory.pdf
- https://uploads.strikinglycdn.com/files/907df2b5-7f14-47c3-be0a-fe34cd905f12/figavijogejalika.pdf
- https://uploads.strikinglycdn.com/files/5bcf9e5a-dc47-4fc9-b9b3-c552e1e60b3a/how_to_calculate_half_life_algebra_2.pdf
- https://uploads.strikinglycdn.com/files/34efbc6d-3b19-45a1-95ec-c12b67a789eb/vonolokifakesagijegezoxu.pdf
- https://uploads.strikinglycdn.com/files/fb0ed821-c195-416c-a473-b848ab80fb8c/best_3_ton_floor_jack_harbor_freight.pdf
- http://lopovimefadepom.epizy.com/juguxevifer.pdf
- http://zexodelovakeg.rf.gd/fugeme.pdf
- http://lebodixo.epizy.com/75696488680.pdf
- https://uploads.strikinglycdn.com/files/a463edfb-e856-4068-bfca-304d059d6bce/1015555134.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000de67.binf5fa5982e1d06f45cbdbe2d47bb430d1e6c7d6b96dd998c38b8d7f661a05694d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDE67 | 5700 bytes |
font_01_sfnt_off0000f1e3.bin1fdd27aa1cef05859ca27202e189a395395e350bab4a36d47f727d1a897bb7e9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1E3 | 10460 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.