MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains heuristics indicating it is a phishing document and hosts a link farm. The embedded URL points to a domain that appears to be part of a phishing campaign, using a game release date as a lure. While no scripts were directly extracted, the PDF structure and URL usage are consistent with malicious phishing documents.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=cyberpunk+2077+release+date+changed
- https://cdn.sqhk.co/tutabalero/eT4Wt17/68204554413.pdf
- https://cdn-cms.f-static.net/uploads/4378155/normal_606c75eee76f1.pdf
- http://psylath.com/acer_chromebook_15_cb5-571-c1dz_specsrqr1o.pdf
- https://cdn.sqhk.co/xevowuto/ijekmgd/lightroom_presets_app_store.pdf
- http://copyright-supporthelp.com/18281816704mb232.pdf
- https://cdn.sqhk.co/fuxiwimemo/VhajipR/87641174190.pdf
- http://zzzmmmmejjj.space/detailed_design_documentn999r.pdf
- https://cdn-cms.f-static.net/uploads/4409798/normal_60104a2387b51.pdf
- http://lujedovijoluje.22web.org/facts_about_mathematics.pdf
- https://cdn.sqhk.co/vugiboba/ljaaigy/flir_tools_templates.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://84d655c4-d84a-4a0c-9c32-0387925bd622.filesusr.com/ugd/6233da_8e9eaec68cca472989bb097e92ce16c4.pdf?index=true
- https://4c2674ec-1430-4cec-a455-d6a35d10586e.filesusr.com/ugd/38955b_2d51181c0cdd4de9b45452ef97ecf311.pdf?index=true
- http://kipuredig.rf.gd/laboratory_apparatus_in_chemistry_and_their_functions.pdf
- https://c335e157-9962-4e43-983a-f5fcf491c4e2.filesusr.com/ugd/a09b09_a9c91614914b4023b30d138191c135ff.pdf?index=true
- https://a6053a4b-6066-498d-92a8-7748b68531bc.filesusr.com/ugd/5f0d2f_e6ef08a2981244d7b5c0dfc024bec52f.pdf?index=true
- https://2061f665-9309-41a6-981d-137229ee7e60.filesusr.com/ugd/eb2fe6_9d5649fc12544f6a94a589255b0b7434.pdf?index=true
- http://wisijogasego.epizy.com/one_of_us_is_lying_tv_show_auditions.pdf
- https://711a90e7-97f2-4eab-8690-3003ec1e9b64.filesusr.com/ugd/a0905b_54ed30c91c3646208d463a0ce10a152c.pdf?index=true
- https://4123e755-5e7e-4fb8-b167-49ba90d37259.filesusr.com/ugd/fd3290_c89f9cd7219547039218c93c2839ea9f.pdf?index=true
- https://9d1e48ad-bcd7-4831-9b7b-7108443a63b6.filesusr.com/ugd/136d07_10ae93c00866488bbc27a2f19d1c79f1.pdf?index=true
- https://d8ec88ce-93b1-4b83-b294-7016fd5b5063.filesusr.com/ugd/366252_5dc67fbf9b1945d89dbdbfa5af09332f.pdf?index=true
- https://63c5840e-267c-49ed-94d3-fc9f9d8b9c0b.filesusr.com/ugd/8c5bc8_1e338c08ef40407db07356bb7163a3a0.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1cc.bin590bb05a359ef375e797627dd7a359c7af9800d494849a29618a80b0a6517318 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1CC | 5900 bytes |
font_01_sfnt_off000105e4.bin19023d646a7e32eccbdac5d52989fd22fe756ae76f3db86e4ff3e73f9a2c17dc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x105E4 | 10324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.