MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The heuristic firings point to the creation of a link farm with numerous external URLs, suggesting a phishing or SEO poisoning campaign. One of the embedded URLs, https://kuzutuzo.ru/wix?keyword=crayola+silly+scents+marker+maker+color+mixing+guide, is particularly suspicious and likely leads to a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/wix?keyword=crayola+silly+scents+marker+maker+color+mixing+guide
- https://bosubunu.weebly.com/uploads/1/3/4/6/134693877/2622301.pdf
- http://crispyset.online/how_to_analyse_your_artwork_gcse1hqgl.pdf
- http://vovpomnim.ru/sujet_brevet_franais_washington_2019kjy9o.pdf
- http://swiss-gear.shop/63267263092dbq6x.pdf
- http://money-team.site/pukuxarefirogumelurubajozept.pdf
- http://springtea.space/29219950138wrad1.pdf
- https://gepadagonuvo.weebly.com/uploads/1/3/0/7/130775626/cf1fe2187d6.pdf
- http://nicechange.space/zenifatuvuxupujavajekq7u8x.pdf
- https://takijotirodone.weebly.com/uploads/1/3/1/6/131637658/909a1a9b38ba9.pdf
- http://jushq.pro/hayward_swimclear_cartridge_filter_manualjudqn.pdf
- http://idealicagocce.site/how_to_replace_mossberg_500_forendn526t.pdf
- https://femodamokej.weebly.com/uploads/1/3/4/5/134529999/ratunir.pdf
- http://flipping-car.online/bofimime3wueu.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://f039f7e9-c7fa-441d-bf3d-2f0e35d6be10.filesusr.com/ugd/80685d_4500cd7316874aac93243ba3aef0b132.pdf?index=true
- https://s3.amazonaws.com/nasitevu/1021924023.pdf
- https://e082b6be-64c0-45f6-a8ff-82b9c6f476f0.filesusr.com/ugd/1479de_8ffe567bd93c458a83a8b06a972d0fdf.pdf?index=true
- https://uploads.strikinglycdn.com/files/ecf129db-7884-4468-9f66-8acef69a448f/exide_battery_charger_price.pdf
- https://uploads.strikinglycdn.com/files/c7de2e98-e4d4-48e1-b185-1ae97610b231/39835965899.pdf
- https://uploads.strikinglycdn.com/files/cbaea601-7d29-4387-8701-32c862a14204/bufeludoravu.pdf
- https://s3.amazonaws.com/padosumifubobo/dough_sheeter_for_sale.pdf
- https://s3.amazonaws.com/kukupunopedon/vekotokigix.pdf
- https://a1c9bafd-2917-4c1b-b79c-a4b44a941470.filesusr.com/ugd/f0f215_05be4088454e4d1392da3027ab392d6b.pdf?index=true
- https://528a8416-53f4-4693-bcf0-540471887af1.filesusr.com/ugd/c3aa89_2cdaed85c9fe4c159c9dac1101dda45c.pdf?index=true
- https://d19688e0-347f-4d9d-8cb3-d47c6e049f3d.filesusr.com/ugd/c618e9_28ab28dc03ef4e6aa47b39e576a8acbc.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e691.bin469bd3c9699e041a9f1f491fc6f4104dbef2cc20f14d6cd28929bd844ccef7cb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE691 | 5400 bytes |
font_01_sfnt_off0000f8df.bin464e5db6cd2d295d8c142724f97fec35fc6618957392dab06ceee8b68ca9c18c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF8DF | 11428 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.