MALICIOUS
124
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file contains multiple embedded URLs, with one prominent URL pointing to a suspicious domain that is likely used for phishing or malware distribution. The heuristic 'PDF_SEO_DISPOSABLE_LINK_FARM' indicates a link farm on disposable hosting, further suggesting malicious intent. Although no scripts were explicitly extracted, the presence of embedded URLs and the ML classifier's high confidence score point towards a malicious document, likely delivered via spearphishing.
Machine Learning
- Nyx PDF Classifier malicious score 0.8846
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/aws?utm_term=bumpy+ride+full+hd+video+song
- https://cdn.sqhk.co/fulaxanew/hAiijfM/rovudozedejopabetiw.pdf
- https://gebusoju.weebly.com/uploads/1/3/0/9/130969184/7578716.pdf
- https://cdn.sqhk.co/noxomosanena/jhhjfSq/d2_head_basketball_coach_salary.pdf
- https://cdn.sqhk.co/jabosuve/iiVyjgy/23033698507.pdf
- https://zoxujaratufopa.weebly.com/uploads/1/3/5/3/135399722/8626774.pdf
- https://vifegozotamideb.weebly.com/uploads/1/3/4/2/134236473/081c4.pdf
- https://nukukenodaxuw.weebly.com/uploads/1/3/1/3/131384044/18f3c96b.pdf
- http://wivejudotimog.22web.org/13_colonies_map_worksheets.pdf
- https://cdn.sqhk.co/wanevakaxuma/I8Mjgic/almost_break_time_in_spanish.pdf
- https://cdn-cms.f-static.net/uploads/4366397/normal_5fdaacb211ad3.pdf
- https://cdn.sqhk.co/fudopalizew/a5o0Wif/board_games_store_near_me.pdf
- https://s3.amazonaws.com/tixedujegibex/98766101511.pdf
- https://s3.amazonaws.com/kujapomib/beaks_of_finches_regents_lab_answers.pdf
- https://s3.amazonaws.com/lofese/24100115109.pdf
- http://toramowajo.epizy.com/pikofomejo.pdf
- https://s3.amazonaws.com/wazorixekunafob/kixavikasenovoxemevudu.pdf
- https://s3.amazonaws.com/mefonevimimix/sosuronegutula.pdf
- https://s3.amazonaws.com/jalasilunaz/98698671738.pdf
- http://fobupozomorefiw.epizy.com/making_money_spending_money_ielts_reading_answers.pdf
- http://tosodesuvivat.epizy.com/employment_contract_template_free_new_zealand.pdf
Open this report in the interactive analyzer, or submit your own file for analysis.