MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, many of which are part of a link farm designed to manipulate search engine results. The primary URL, https://dafemum.ru/wix?keyword=adding+periods+to+run+on+sentences+worksheet+answers, suggests a phishing or malware distribution attempt disguised as educational content. The ML classifier and ClamAV detection strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/wix?keyword=adding+periods+to+run+on+sentences+worksheet+answers
- https://cdn.sqhk.co/minamojazi/gjDhfzS/64153264676.pdf
- https://cdn.sqhk.co/foxoxaze/iexQhbi/rise_up_imagine_dragons_lyrics_karaoke.pdf
- https://cdn.sqhk.co/mukibusu/DidAUhj/spacex_crew_dragon_landing_date.pdf
- https://cdn.sqhk.co/beratinuga/lRVt9gf/roblox_download_chromebook_acer.pdf
- https://cdn.sqhk.co/zetanitanedo/ggghjXP/mefibog.pdf
- https://cdn.sqhk.co/zewesifadeka/NfLp6ih/24985947644.pdf
- https://cdn-cms.f-static.net/uploads/4383131/normal_602756af37252.pdf
- https://cdn-cms.f-static.net/uploads/4423462/normal_6025e52caf4be.pdf
- https://cdn-cms.f-static.net/uploads/4450870/normal_5fe813d388847.pdf
- https://cdn.sqhk.co/valipovu/3Uh7iaf/theme_park_island_code_fortnite.pdf
- https://cdn.sqhk.co/mogizilo/fKEZGZN/first_aid_tips_for_burns_and_scalds.pdf
- https://cdn-cms.f-static.net/uploads/4391915/normal_601d58fd65abf.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/6548c12f-97f5-4fdf-ab25-d6328b66d9c9/how_to_fill_out_the_secret_blank_check.pdf
- https://64e18f06-8a0e-4dc1-8427-9dd81b4bff36.filesusr.com/ugd/baa514_0f2144537cb14a73a5e1999482f14220.pdf?index=true
- https://59e5a08b-0d8d-455f-a3a7-35a3b781ab3e.filesusr.com/ugd/784815_87f216c6ead34c539ed40df18fc9cd5a.pdf?index=true
- https://aabf49e0-5477-4fd2-8456-a986ef8f2a87.filesusr.com/ugd/9e14ca_88a9772ec16b479a84d94f2f9947366c.pdf?index=true
- https://be1d055c-b83b-422e-9e68-1bf13cef350c.filesusr.com/ugd/5b1e3c_7a8fdd475dba437e9695a76262bb2794.pdf?index=true
- https://uploads.strikinglycdn.com/files/6913524a-50f6-41e2-af9d-8586b3a725ed/jaxub.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ce7a.binb4a5a803c005ec8fce62064730c8e8e7f983d8fb38f07f6a0a2b6f95aee75044 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCE7A | 5448 bytes |
font_01_sfnt_off0000e117.bin6008bb6a2d78747dff1f68c06a1cc39d6b64ae312c54fe0f286a01016cfd1684 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE117 | 9900 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.