MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified by the 'PDF_SEO_LINK_FARM' heuristic, suggesting a malicious intent to redirect users. The ML classifier and ClamAV detection strongly indicate this PDF is malicious, likely a phishing or trojan delivery mechanism. While no scripts were explicitly extracted, the presence of numerous external URLs points to an attempt to lead users to potentially harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://seumenha.ru/strik?utm_term=how+long+to+run+a+half+marathon+for+a+beginner
- https://static.s123-cdn-static.com/uploads/4371246/normal_600513fe3ca79.pdf
- https://cdn.sqhk.co/vixawutozama/cAgiMtJ/jurassic_world_the_game_apk_hack.pdf
- https://cdn-cms.f-static.net/uploads/4451033/normal_6043c357057d5.pdf
- http://mamuxorap.getenjoyment.net/a_b_whole_square_all_formula.pdf
- https://cdn.sqhk.co/xufojidaju/ic95ic8/cae_exams_book_2015.pdf
- http://winoxolupuvil.getenjoyment.net/rannar_boi_in_bengali_free_download.pdf
- https://cdn.sqhk.co/memenewo/kpgiX11/real_time_traffic_golden_gate_bridge.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://wozimape.onlinewebshop.net/xosagijezasuj.pdf
- https://ddb0fe67-a09a-413d-b59a-c21b1dde3186.filesusr.com/ugd/3f0e57_cade80aa81034586844a21edbed61204.pdf?index=true
- http://wuragumok.atwebpages.com/canon_in_d_fingerstyle_guitar_tab.pdf
- https://88966db1-4a83-4446-b941-f65022a6235f.filesusr.com/ugd/928e0f_37d83234632b4daea06b081d3580a043.pdf?index=true
- https://uploads.strikinglycdn.com/files/e5388f8b-d2d4-40f5-934d-f2d4aaf3f2bf/how_to_print_adhesive_vinyl_cricut.pdf
- https://cd5075e9-4951-46bd-8d13-413fdd501c9b.filesusr.com/ugd/eceaf1_9168611cc8654e24a8fb2b9a6c4bd5cf.pdf?index=true
- https://44f39d5c-a655-4437-91b6-62b11e148e71.filesusr.com/ugd/eb4c03_596d280772cf45afa6af2f2b40113e54.pdf?index=true
- https://fa0867c9-8cf0-46f9-bfae-aad8e49c21f3.filesusr.com/ugd/cdba2c_270b6c72fb844876b129fa122baef366.pdf?index=true
- https://uploads.strikinglycdn.com/files/9c2cce97-a964-4b0d-b5d6-a6e97ef388f7/petivenazasudot.pdf
- https://6e3eaeb2-b9dd-4462-8b56-96c59beebd9a.filesusr.com/ugd/dcc11b_8a49e76b83ea4417b53b13778723c9fa.pdf?index=true
- https://09d56968-2ae9-412d-ad86-e67dc63a1c23.filesusr.com/ugd/e8b91f_ffe32bca31944dccab6d9a298482019c.pdf?index=true
- http://belibivizonojo.myartsonline.com/71858044201.pdf
- https://uploads.strikinglycdn.com/files/c7013b7e-59b4-4730-9329-06b7e846f499/zesabegututiwi.pdf
- https://cf4de027-7369-46c2-bf93-d69cabef2b5e.filesusr.com/ugd/868b90_58131b929dd74701b4a8a281a10af00a.pdf?index=true
- https://a3c35cc3-4a3f-4d41-ab51-8b3e4b114d30.filesusr.com/ugd/2b25b5_603e3fc99c784c7e8c75d17d5917df24.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fa97.bine2c027d66edba143816c634f4b21641563464f277c5a0a504d03c1436a3898ec |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA97 | 5196 bytes |
font_01_sfnt_off00010c30.bind4b92b231a61466ae20a162e15b9afd507142246fb4bf03f23fb5e4475c69b50 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10C30 | 10552 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.