Malware Insights
This PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. It contains a large number of external links, many pointing to disposable domains, suggesting a link farm or SEO manipulation tactic. One prominent URL, 'https://jumiwimov.ru/strik?utm_term=samsung+a10e+review+verizon', indicates a potential phishing lure related to product reviews. No scripts were extracted, but the PDF structure and numerous external links strongly suggest a malicious intent to redirect users to potentially harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/strik?utm_term=samsung+a10e+review+verizon
- https://static.s123-cdn-static.com/uploads/4373992/normal_5fc5a0b782a27.pdf
- https://cdn-cms.f-static.net/uploads/4500678/normal_6033a9d4a689f.pdf
- http://support-copyrighthelpservice-about.com/82050083303wyso7.pdf
- http://mojenisijita.mywebcommunity.org/gogojadetoxevukunavajox.pdf
- https://cdn-cms.f-static.net/uploads/4403947/normal_6068353b8736d.pdf
- https://cdn-cms.f-static.net/uploads/4383802/normal_606dfffae9682.pdf
- http://dreabling.online/what_is_the_formula_for_calculating_the_dose_of_medication_based_on_body_surface_areaup9t5.pdf
- http://amst-watch-v1.club/clothes_dryer_repair_service_near_mek28w6.pdf
- http://help-business-media.com/skyrim_the_fallen_glitch_jarlw4211.pdf
- http://vomidujoma.scienceontheweb.net/honda_side_by_side_1000_for_sale.pdf
- http://mumolazesinidix.getenjoyment.net/ancient_egyptian_civilization.pdf
- http://fuvidevifa.scienceontheweb.net/how_to_write_a_mystery_story.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://doritiwenoxa.onlinewebshop.net/pocket_atlas_of_sectional_anatomy_thieme.pdf
- https://9eaa565e-fb97-40b4-b096-d6760803f699.filesusr.com/ugd/55e2c6_a031fe595141480cbc19695127ae2b87.pdf?index=true
- https://50aad03f-9d2a-47e6-be13-abd12f321b17.filesusr.com/ugd/3fd638_93acf7d435a549e09a4b102331f7e225.pdf?index=true
- https://dcd55a6f-f4d9-4ab7-9ea0-0dac4ffa5d6f.filesusr.com/ugd/f7cbe4_32f82f89cea040358cbe1c24922315a3.pdf?index=true
- http://gutekuretejapoj.onlinewebshop.net/sepux.pdf
- https://33b7cf8b-1cb2-46d9-9063-17e97cba5e80.filesusr.com/ugd/9edd50_c2b3ad82ed564d0c9a2beb52654a9d18.pdf?index=true
- https://5a060084-92f5-4e09-b02e-bbac8bb45871.filesusr.com/ugd/05c943_0200e830ec6b424282eaa501bd982ee4.pdf?index=true
- https://451b78f8-089e-4d4d-bc4b-60abb621f7e6.filesusr.com/ugd/7ef0dc_5e77e27963f84af1883b1d6190728727.pdf?index=true
- https://da99f664-88c7-4a27-98aa-0bbcec2e8f57.filesusr.com/ugd/66f3f9_9f2c6950835b4f09b98714cb5e4718ee.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ef56.binebb8a50ba14d40296e631186b0e849f9fb76cc88280a6b8026d0ae00be46d774 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEF56 | 5472 bytes |
font_01_sfnt_off000101ec.bin43c1f499c6b1538c19703858312f01e7c8c315bb3560452942dee8db73b3ac91 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x101EC | 4136 bytes |
font_02_sfnt_off0001115c.binfd41abaa5797108688d5e84b038de9427035f2f3516de21140c4c030d1b5155b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1115C | 11688 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.