MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a lure related to Minecraft errors, directing users to a suspicious URL. The PDF_SEO_LINK_FARM heuristic indicates a large number of external links, suggesting a link farm or phishing operation. ClamAV detection and ML classification confirm the malicious nature of the document, likely used as a spearphishing attachment to redirect users to malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/wix?keyword=minecraft+null+error
- https://cdn.sqhk.co/purizepore/Fp8Kgg4/an_innocent_warrior_mp3_free_download.pdf
- https://cdn.sqhk.co/zamokaxu/hck0jjd/california_unlimited_speed_limits.pdf
- https://cdn.sqhk.co/sobexofap/gdupQif/bawozazovawidabofunirodo.pdf
- https://cdn.sqhk.co/duzixulok/ijihigO/starbucks_heart_cup_2020.pdf
- https://static.s123-cdn-static.com/uploads/4402250/normal_5fce7a8acba85.pdf
- https://cdn.sqhk.co/madagijoj/iiagdig/tenok.pdf
- https://static.s123-cdn-static.com/uploads/4490917/normal_60057c3fd497a.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://s3.amazonaws.com/nawuvud/analysis_of_kartilya_ng_katipunan.pdf
- https://uploads.strikinglycdn.com/files/ca5fcd08-c569-49f9-8e69-fbafe006e7d3/36277951791.pdf
- https://s3.amazonaws.com/vixuwogetiv/zafefunifiruzogub.pdf
- https://s3.amazonaws.com/zategafozasiru/19754302001.pdf
- https://e4034479-4ead-418b-af8c-5be8dc72bdbe.filesusr.com/ugd/1e8759_99ce10935d8c4441910ea0c1c4c39d62.pdf?index=true
- https://s3.amazonaws.com/fedufiporara/aprender_ingles_desde_cero.pdf
- https://s3.amazonaws.com/kujapomib/spatial_analysis_and_modeling.pdf
- https://s3.amazonaws.com/daraniwekamidir/garukuw.pdf
- https://ed4d48c2-14ea-47f5-a89a-b82193587323.filesusr.com/ugd/8ce377_ba57f2437acb44ca90d766b7149eff37.pdf?index=true
- https://a3de454e-1598-42bb-a259-4eb69c42f179.filesusr.com/ugd/fb5067_805fb20e4fd8415680b90b2536e8d36b.pdf?index=true
- https://uploads.strikinglycdn.com/files/94373c9f-68b8-49b2-993d-0a4e2e961de1/76648929571.pdf
- https://s3.amazonaws.com/fobupojowojon/sample_business_introduction_letter_introducing_company.pdf
- https://s3.amazonaws.com/fomudebipefasu/marriage_allowance_form.pdf
- https://uploads.strikinglycdn.com/files/0c85db21-8196-4c79-8672-49a006f976fa/sonic_adventure_2_gamecube_controls.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e431.bin46459f59727f99e7b105e9e136d40da16253c56fcacb07625812504c918b71bc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE431 | 4584 bytes |
font_01_sfnt_off0000f3ca.bin926c0707d6efcc1cfc96c6a5fef3b69588a8c71ef6e1932a574f0dde58482030 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF3CA | 14364 bytes |
font_02_sfnt_off0001213a.bin05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1213A | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.