MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The PDF contains a large number of external links, many pointing to other PDFs, suggesting a link farm or SEO poisoning attempt. One prominent URL, 'https://baarspo.ru/strik?utm_term=what%2527s+the+most+valuable+comic+book+ever+sold', is likely part of a phishing or malware distribution scheme. The 'SE_INVOICE_LURE' heuristic further supports the idea that the document is designed to trick the user into clicking malicious links.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://baarspo.ru/strik?utm_term=what%2527s+the+most+valuable+comic+book+ever+sold PDF link annotation
- https://bofejaximolapob.weebly.com/uploads/1/3/4/7/134751884/6750090.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4392441/normal_60012e880e64d.pdfIn PDF document text
- https://numurivigafezu.weebly.com/uploads/1/3/4/3/134390613/gekujesodajalofol.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4476578/normal_5fceceddb9f26.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4451766/normal_5fce6a3c2c1f2.pdfIn PDF document text
- http://alsamcctv.com/epic_astro_story_layout4ina6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4451212/normal_5fe78dec2118a.pdfIn PDF document text
- https://zigamebujadosa.weebly.com/uploads/1/3/4/7/134745820/gigeme.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4482012/normal_5ffdb86b61443.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/fotepopunaj/welekuvaridewibowipoti.pdfIn PDF document text
- https://s3.amazonaws.com/jumedemimo/minister_service_alberta.pdfIn PDF document text
- https://s3.amazonaws.com/kiremefegonar/levadozusefa.pdfIn PDF document text
- https://s3.amazonaws.com/mokixetat/can_an_essay_be_6_paragraphs.pdfIn PDF document text
- https://s3.amazonaws.com/pipaneku/block_ads_and_popups_in_chrome_android.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010bf3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10BF3 | 5492 bytes |
SHA-256: 4836f3c8da102d6f9be618df8c67a4afc6e73631a860d783edede2618285a320 |
|||
font_01_sfnt_off00011e88.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11E88 | 10712 bytes |
SHA-256: a55c74f12b2aef11e53b4307432cf0fa173df7fdbcb8ade0371f01b73245655e |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.