MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The PDF contains heuristics indicating it is a link farm and a phishing lure, with a high ML score and ClamAV detection. The document body, though partially corrupted, suggests a financial analysis context. The embedded URL 'https://zajinet.ru/wix?keyword=cash+flow+statement+analysis+pdf' and the first URL from the link farm 'http://sazojojuw.rf.gd/pawuxelosofajuf.pdf' are the highest priority IOCs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/wix?keyword=cash+flow+statement+analysis+pdf
- http://xubanapirobula.mypressonline.com/which_city_is_less_cold_in_canada.pdf
- http://danivufulof.iblogger.org/61573916342.pdf
- http://lebojabufi.medianewsonline.com/what_do_you_wear_to_a_garden_party_wedding.pdf
- http://zunuruxeguxifi.mygamesonline.org/logitech_k120_wired_usb_keyboard_review.pdf
- http://zawugudumi.getenjoyment.net/painting_kitchen_cabinets_gray.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://sazojojuw.rf.gd/pawuxelosofajuf.pdf
- https://edcb5511-827b-40b0-97c1-3499c313f96b.filesusr.com/ugd/0779a3_7776669cad2241299b7750eae448d9c0.pdf?index=true
- http://wugujub.onlinewebshop.net/moultrie_mcg-13034_manual.pdf
- https://s3.amazonaws.com/xoferuzu/7067342754.pdf
- https://s3.amazonaws.com/belapawerezuju/43838816560.pdf
- https://s3.amazonaws.com/daniwodug/gba_roms_free_coolrom.pdf
- https://171e2b11-24ea-4535-acac-f971ec821c4b.filesusr.com/ugd/a07927_3a4185f379cc4299b1d8e863ead38175.pdf?index=true
- https://s3.amazonaws.com/tapelu/avg_antivirus_free_with_activation_key.pdf
- https://6632aaff-1fe9-4f1d-acb3-7d444e457837.filesusr.com/ugd/ce4b7c_75280096829c488b8866ead0837df593.pdf?index=true
- http://totuxivez.onlinewebshop.net/articles_rules_download.pdf
- http://zusaxadixuxot.myartsonline.com/vinineregedopezo.pdf
- http://juripijesem.rf.gd/ginakoludi.pdf
- http://nupuzasig.epizy.com/literuwujokotibuveso.pdf
- https://s3.amazonaws.com/rodakarugupoko/where_can_we_see_christmas_lights_near_me.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1fe.bin9082d682a9dea573079919643b42b6fe0c6357bce776a7807243204b2e57a6ee |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1FE | 5284 bytes |
font_01_sfnt_off000103ee.bin418e9768367009f722fdc5d2238cd45253ce719d9f2299b431331ef1c1751569 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x103EE | 10408 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.