MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by multiple heuristics, including a critical ClamAV detection and an ML classifier. It contains a large number of external links, characteristic of a PDF link farm, with the primary malicious URL being https://jumiwimov.ru/strik. The document body is heavily obfuscated, but the presence of PDF_SEO_LINK_FARM and PDF_URI heuristics strongly suggests an attempt to direct users to external sites, likely for phishing or to download further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/strik?utm_term=ge+spacemaker+microwave+xl1800+light+bulb
- http://dezunanerab.iblogger.org/how_much_does_it_cost_to_maintain_a_cessna_150.pdf
- http://jovekigapovokeb.22web.org/hipotonia_y_atonia_uterina.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/bulalowisu/yelling_cat_meme_template.pdf
- http://zeduneku.rf.gd/vomoxofupupimoviririjanuf.pdf
- https://s3.amazonaws.com/donarepemi/los_mejores_cursos_de_ingles_cdmx.pdf
- https://uploads.strikinglycdn.com/files/704956e7-3475-4c90-bbab-55bdc4ab7b0f/binebinolifepojitiwawuzok.pdf
- http://buvumitibeve.rf.gd/nausea_sartre_portugues.pdf
- https://uploads.strikinglycdn.com/files/0f724d47-03e8-4332-8244-7baa9b28703c/computer_book_store_near_me.pdf
- https://s3.amazonaws.com/ximupuv/interesting_facts_about_ancient_egyptian_gods_and_goddesses.pdf
- https://2a4c341d-9af7-4f89-b48a-1b926ad6ced7.filesusr.com/ugd/dd6616_3dd674fb6d5c4af08875fd41848a3db4.pdf?index=true
- https://4a1cfc67-5981-466d-a13b-75576fe7431f.filesusr.com/ugd/64e449_5754b367154048659c8919f8b1d4d980.pdf?index=true
- https://79d86aa2-23c4-4aa0-a0dc-c16ac59ae55d.filesusr.com/ugd/ecb701_d7dde1e2d98748f3b067ae590fb637fb.pdf?index=true
- http://pasumogebono.rf.gd/net_jrf_sociology_syllabus.pdf
- https://s3.amazonaws.com/tonisefoteka/86122523604.pdf
- http://xumesata.epizy.com/24110705628.pdf
- https://264aa3b4-28a3-4a3b-9cf4-afdf28ba9476.filesusr.com/ugd/28a074_6889ebeb08014bb8834674645183a917.pdf?index=true
- https://49432a94-54bc-4d13-9d12-ea41d731e1b8.filesusr.com/ugd/a7c689_0096dd56d5644bb19886246f2c446d17.pdf?index=true
- http://naresukewuvaz.epizy.com/zomivurinawofesawuko.pdf
- https://s3.amazonaws.com/wurivuve/62266144448.pdf
- https://s3.amazonaws.com/kiwopusafize/85581834663.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e7a1.bin88f9ab4fe0b0fa83d0de49a32bcada4f43b323ec77093e2f1f006691dce54d85 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE7A1 | 6188 bytes |
font_01_sfnt_off0000fcac.bina50d466859f583123519aa3d24ee6b26e9ef9e115172e48646b5b66c52497a4f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFCAC | 11152 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.