MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was identified as malicious by ClamAV and an ML classifier, exhibiting characteristics of a phishing lure. The heuristic 'SE_PAYMENT_REDIRECT_LURE' indicates the document attempts to trick users with fake payment or bank detail change instructions. The presence of numerous external links, including one to 'golowaki.ru', suggests a redirection to a malicious site for credential harvesting or further exploitation.
Machine Learning
- Nyx PDF Classifier malicious score 0.9960
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LUREDocument describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://golowaki.ru/123?utm_term=there+to+be+past+simple+pdf
- https://fopepusev.weebly.com/uploads/1/3/1/3/131383694/rexewudo-lidusomilamo-rasuwatiwek.pdf
- https://cdn-cms.f-static.net/uploads/4463298/normal_60219483808cb.pdf
- http://tramlaweq.online/wolf_of_wall_street_full_movie_watch_online_youtubeefcr6.pdf
- https://nefolebar.weebly.com/uploads/1/3/4/4/134400051/ae04623d3dd9656.pdf
- https://cdn-cms.f-static.net/uploads/4451549/normal_603308e459f8e.pdf
- http://train-home.ru/bengali_panjika_1426_downloadzjha6.pdf
- https://woxazalaxit.weebly.com/uploads/1/3/4/2/134235403/vugin_jitano.pdf
- https://static.s123-cdn-static.com/uploads/4419413/normal_5ffd89975876f.pdf
- https://static.s123-cdn-static.com/uploads/4476434/normal_5fca2460b9d07.pdf
- https://zugozoriv.weebly.com/uploads/1/3/4/7/134770463/xizekipo.pdf
- https://static.s123-cdn-static.com/uploads/4367286/normal_5fe3f13b1ff3f.pdf
- https://cdn-cms.f-static.net/uploads/4501659/normal_5fe896dfefdd6.pdf
- https://cdn-cms.f-static.net/uploads/4475737/normal_60354af380b60.pdf
- https://cdn-cms.f-static.net/uploads/4443372/normal_6019c116cdf99.pdf
- https://jipafedi.weebly.com/uploads/1/3/0/8/130813136/bedofi-jawef.pdf
- https://cdn-cms.f-static.net/uploads/4406229/normal_60579407331d6.pdf
- http://hocostyle.ru/19247701853hvjl6.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/40f72943-4161-42d3-a609-35270c3e6305/67660153077.pdf
- https://538d8494-0c7d-401a-b890-0485f6bc7bca.filesusr.com/ugd/29c71c_00a146c901574b81a7e39a6fd4d58667.pdf?index=true
- https://uploads.strikinglycdn.com/files/a9acaec6-a1d8-4bac-ba26-f44e57ce9a13/79057658226.pdf
- https://da18e6a8-d720-42de-a88c-3f13daad7efb.filesusr.com/ugd/08fe48_dbdf63d2c2f84d0883297e2eb07e737b.pdf?index=true
- https://uploads.strikinglycdn.com/files/4309637b-aa60-4a7b-b072-15d2d0fedf7a/metroid_2_dx_cartridge.pdf
- https://uploads.strikinglycdn.com/files/3740dc42-4d24-4962-88cd-eb7c9bc5e175/how_to_get_a_boarding_pass_on_allegiant.pdf
- https://46d16763-6c5f-4e19-aa2c-3f4071fcbec2.filesusr.com/ugd/26f730_a39cf17a09604c4db1b27968afccc4f9.pdf?index=true
- https://11484d69-1612-41b9-9199-165df1f08223.filesusr.com/ugd/e2f197_c11de60ed5a4447d821f62c9792504a8.pdf?index=true
- https://8569cc17-8b2a-4187-ace0-95b0550b99f0.filesusr.com/ugd/d6eede_62a2853ae8f646ab9234fe08c0019df2.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f2f2.bin7ac7287aba3dae08c7433507f38f0aace64c74b1f917a928e1a7772af0f08bab |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF2F2 | 5372 bytes |
font_01_sfnt_off00010501.binb5f6acb8cadee81cb49aa35e520526ac7fa212964e51bfa781a116899d87c47e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10501 | 11000 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.