MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, many of which are part of a link farm, suggesting a malicious intent to drive traffic to potentially harmful sites. The ClamAV detection and ML classifier strongly indicate malicious content, specifically identified as a phishing trojan. While no scripts were directly extracted, the PDF structure and embedded URIs point towards a tactic of redirecting users to external resources.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/award?keyword=iodine+deficiency+disorder+programme+pdf PDF link annotation
- https://fosobezi.weebly.com/uploads/1/3/4/8/134898374/texugudimavani.pdfIn PDF document text
- https://cdn.sqhk.co/dugelabomaw/ifWOjfl/zowijo.pdfIn PDF document text
- https://tonavibete.weebly.com/uploads/1/3/4/7/134748981/fae06fd654bc.pdfIn PDF document text
- https://vowijavig.weebly.com/uploads/1/3/4/3/134319359/nofunol_namawewixe.pdfIn PDF document text
- https://vajinivokesele.weebly.com/uploads/1/3/5/3/135326698/tirururajo.pdfIn PDF document text
- https://cdn.sqhk.co/suxepemup/jh5icig/the_wolf_hunters_wikipedia.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/pasawe/delta_table_saw_parts_36-540.pdfIn PDF document text
- https://s3.amazonaws.com/fewunadupop/sesegutoxegepenagefo.pdfIn PDF document text
- https://s3.amazonaws.com/nevowimo/dixufemexi.pdfIn PDF document text
- https://c183b790-cb34-49aa-848e-1a9f2b14dda3.filesusr.com/ugd/d8966e_d548df621e604ea09f99a9fc502f85e4.pdf?index=trueIn PDF document text
- https://72dfff08-f6cb-4f5d-aaac-ebe71175d6a6.filesusr.com/ugd/c268f7_46bb0ebd49ba4a03aea0a5da19d1a4f3.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/nigimul/defense_form_deoxys_raid_guide.pdfIn PDF document text
- https://fb413987-6e77-4bf1-aaa6-e97eb550fbee.filesusr.com/ugd/108936_8990a9d834da49fe99cd8f77d0378f32.pdf?index=trueIn PDF document text
- https://d8acad56-eb9a-42d1-a06c-a695c5b02328.filesusr.com/ugd/0ad6c7_9340d9304ece4392bb0d8636e8df7b95.pdf?index=trueIn PDF document text
- https://4e33067b-0f13-4bed-bb9c-ea95f768fd7c.filesusr.com/ugd/23924c_bb76c64b987b473099f3ec0dafeeb0e1.pdf?index=trueIn PDF document text
- https://87b84290-c0b3-4c73-97a1-3d59c64c3f69.filesusr.com/ugd/c638b7_24ce27ccfa83492784ebfc4311e81825.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/e312e82e-6902-4b71-b873-9ab6f549c5a6/45247140886.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6a72accd-3a40-4e02-aa25-a0147493c54f/65546273946.pdfIn PDF document text
- https://da99f664-88c7-4a27-98aa-0bbcec2e8f57.filesusr.com/ugd/66f3f9_38c8c25aeebe4751bf3156cce21cce65.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/gezetega/62931089541.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1b1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1B1 | 5484 bytes |
SHA-256: 89afe0ccfc991c7d2c3444c2fa6c4e4ef5b573fea126b551226c10b40a76ec14 |
|||
font_01_sfnt_off00010454.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10454 | 10640 bytes |
SHA-256: 9f2defa67dae36297ee665a9db0870b869f3a2035e95a419dcbb87143f9a5fdf |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.