MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a phishing or trojan payload. The heuristic 'PDF_SEO_LINK_FARM' indicates the document contains a large number of external links, suggesting it is part of a link farm or SEO spam campaign. The primary IOC is the external URL found in the document body, which is likely the intended destination for the user.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cructi.ru/pbw?utm_term=friction+gravity+and+elastic+forces+worksheet+answers
- https://medogizelolu.weebly.com/uploads/1/3/1/0/131070938/6524199.pdf
- https://jorikune.weebly.com/uploads/1/3/4/3/134371696/453989129fd7.pdf
- https://zifalopo.weebly.com/uploads/1/3/1/3/131379769/waloradolabib.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/8581c235-77ce-4e1d-8905-fa84c0568c80/20079671382.pdf
- http://kipizasuzeda.pbworks.com/w/file/fetch/144416283/gudulafese.pdf
- http://tusawijer.pbworks.com/f/durakimudanunabesovujexow.pdf
- https://uploads.strikinglycdn.com/files/8d1e226d-4247-4a16-a5e9-1ba38f284b9e/namikiwunikomupavop.pdf
- https://uploads.strikinglycdn.com/files/c755a691-f477-478a-a659-eb9bd87311bd/black_skin_white_masks.pdf
- http://wuwazilizos.pbworks.com/f/61581734260.pdf
- https://uploads.strikinglycdn.com/files/b9461a8e-d1c6-4c59-a0bb-8ea0de78c27a/92110281120.pdf
- https://uploads.strikinglycdn.com/files/58b28e2a-0faa-40cf-a826-b94bde05ae44/what_does_type_of_employees_supervised_mean.pdf
- http://zelovoguvunu.pbworks.com/w/file/fetch/144427368/dark_flippy_x_reader_lemon_wattpad.pdf
- https://uploads.strikinglycdn.com/files/f6f556bc-6c57-487f-82a9-7b9c850ff2c6/vovevirute.pdf
- https://uploads.strikinglycdn.com/files/c388a52d-3a7b-41b6-98d3-ac10e7926964/36775735720.pdf
- https://uploads.strikinglycdn.com/files/edddec44-710f-4725-937e-188795b84899/jomomemeruko.pdf
- https://uploads.strikinglycdn.com/files/837b31ed-7378-4519-a04e-508c71ae9ae0/81597095896.pdf
- https://uploads.strikinglycdn.com/files/6b72c434-091b-452d-8fb1-5de71a7442e1/batuwetanaleso.pdf
- https://uploads.strikinglycdn.com/files/b6427e89-af2d-49e5-a152-b625567da009/curso_de_guitarra_clasica_completo.pdf
- https://uploads.strikinglycdn.com/files/b1400844-8d36-4502-9c91-ccb982124471/how_to_activate_autocad_2020_mac.pdf
- https://uploads.strikinglycdn.com/files/d6ab2bea-a839-4b8a-bcfd-ca8087489b30/39900445417.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eb7c.bineed8332f8aa77bfb64e7cfe7c80c4d83bd952b5bc269ccff0fbb04b4a667b30a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB7C | 5556 bytes |
font_01_sfnt_off0000fe80.bin242ff9d603b1682d35af0784b10fb9ecda26db872f1c7548585c91754000c8ff |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE80 | 11152 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.