MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The file contains a large number of external links, suggesting it functions as a link farm or phishing lure. The embedded URL 'https://mezovuduw.ru/wix?keyword=mt+pleasant+beach+access' is likely part of a phishing campaign aiming to redirect users to a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://mezovuduw.ru/wix?keyword=mt+pleasant+beach+access
- https://cdn.sqhk.co/romumoxoleno/fkBTijH/mepamebumazurefipuja.pdf
- https://zagarete.weebly.com/uploads/1/3/4/6/134687236/kivoguroko.pdf
- https://static.s123-cdn-static.com/uploads/4381748/normal_5fccdf6ac9fa3.pdf
- https://cdn.sqhk.co/joraxeneli/iiMijig/58571868067.pdf
- https://cdn-cms.f-static.net/uploads/4495050/normal_60563529ac6ad.pdf
- https://cdn.sqhk.co/fapiwejagiz/aKeLb1i/run_rabbit_run_2017.pdf
- https://cdn-cms.f-static.net/uploads/4467273/normal_6024964f68285.pdf
- https://cdn-cms.f-static.net/uploads/4384459/normal_6016413ede5a7.pdf
- https://cdn.sqhk.co/roratumopiv/4jChdDA/24045280639.pdf
- https://cdn.sqhk.co/pebekaja/s62Mkge/lemowololusipumumupijimot.pdf
- https://cdn.sqhk.co/lovojekaboxi/hghajbR/52692274933.pdf
- https://rumevupalod.weebly.com/uploads/1/3/0/7/130739773/17559a8.pdf
- https://pigikitukapu.weebly.com/uploads/1/3/4/6/134693564/guriko-fibivinifij-nisin-nikigoginawuv.pdf
- https://cdn.sqhk.co/pogadidotilu/jfrieih/flowers_stickers_for_whatsapp_wastickerapps.pdf
- https://cdn-cms.f-static.net/uploads/4446944/normal_6045e44b8b87b.pdf
- https://cdn.sqhk.co/janezewufaj/fhcjiji/airplay_for_windows_7_free.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://ff0b3df2-dc61-4aeb-9024-93fa9b5bc175.filesusr.com/ugd/aa14a9_67b736936c0142b8bbaa25a460633895.pdf?index=true
- https://09972071-4174-499b-90b1-de3619f59f53.filesusr.com/ugd/d1c05f_2eb5b07476d442469a179a278ef9f73d.pdf?index=true
- https://3ea853e4-7f2b-4fb0-9229-b04907a1e321.filesusr.com/ugd/d94095_1485e4b9c88b48c29111c1f74d580430.pdf?index=true
- https://ab25a8b3-4d80-4d4b-93a1-c1347014fa7c.filesusr.com/ugd/8d0191_6e8ca2c063d94ec1a4d162dcb8fb6ad1.pdf?index=true
- https://77a80da1-97a3-4b40-ba11-54c6d232eb66.filesusr.com/ugd/39a0fd_9c61b87f92e54ca68980f3235261c0b1.pdf?index=true
- https://0e627107-309b-4451-a84d-e7064c41fccd.filesusr.com/ugd/04c368_b2a08faf63984677b921600f0b72d924.pdf?index=true
- https://40c507a3-37b7-491f-afd3-f28ba3af1fb2.filesusr.com/ugd/7f5264_c3d79686756443859fc051e10cf3e556.pdf?index=true
- https://9d50af6f-dbf7-41ba-b854-83985329a12b.filesusr.com/ugd/33c377_3009eec39aa946d89b0512c5620354bb.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f886.bin494e78c2f21d38719625d73e95d5dd2c1e86e40c23ae2e8b363a373a58e695dc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF886 | 5068 bytes |
font_01_sfnt_off000109c2.bin303e64d53b618fa899d9dfd0be6ce6b60d2d6600361af2141253cbb25d8c92b4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x109C2 | 10808 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.