MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with a critical heuristic identifying it as a PDF link farm designed for SEO. The primary malicious URLs identified are 'https://xezojetit.ru/wix?keyword=intermatic+heavy+duty+outdoor+timer+manual' and 'http://kuzexamipapoxip.medianewsonline.com/41054439476.pdf'. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for phishing or distributing further malware.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/wix?keyword=intermatic+heavy+duty+outdoor+timer+manual
- http://kuzexamipapoxip.medianewsonline.com/41054439476.pdf
- http://summ-green.fun/gisesegirz7hbo.pdf
- http://deutschebank-meine.com/zeal_spy_apk_downloadnxgeb.pdf
- http://bivaxopepukoxi.getenjoyment.net/acordes_de_acordeon_de_botones_en_sol.pdf
- http://tadefog.medianewsonline.com/33794915102.pdf
- http://fifamarketbot.com/20052212509mtkzz.pdf
- http://trastqort.online/estruturas_de_ao_pfeillgf5g.pdf
- http://duwinijuj.mypressonline.com/bookmark_file_online.pdf
- http://draiwenstore.online/725896527722v9r8.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://93dbb2ad-f1e8-4c6c-adfd-2ef134399473.filesusr.com/ugd/df4650_b03c4680c8014c91b51cfff8ed484dc7.pdf?index=true
- https://s3.amazonaws.com/tuxexi/mavatomof.pdf
- http://suduxegowur.onlinewebshop.net/betaseron_package_insert.pdf
- https://d0f5cf02-e55f-42e7-ba97-8a4d5a2b8368.filesusr.com/ugd/7f59a0_f1836e294f8843d89d16c2096992d3d6.pdf?index=true
- https://0c2a99dd-71fd-4a0d-b96f-672cfa785c21.filesusr.com/ugd/515c54_5290dbeb30c048dea51de3a7e5a67c59.pdf?index=true
- http://zevesijuduma.atwebpages.com/zorba_the_greek_quotes_dance.pdf
- https://f579be4a-c2ec-451d-94ee-532237c06880.filesusr.com/ugd/9f6a24_1213e1b7d9cb4515aa7f4dda29f858ef.pdf?index=true
- http://gakilasefit.myartsonline.com/figegurudepegi.pdf
- https://8d684a1e-4078-49cd-b336-05adf09473b6.filesusr.com/ugd/2b25e8_eb926e7597914002bdafc70caa296e3d.pdf?index=true
- https://s3.amazonaws.com/xebuvuwov/bibliography_format_for_books_mla.pdf
- https://95a57b4d-a24c-4412-bd87-88f4f885d252.filesusr.com/ugd/011e4b_56cba6ed33f14199b6b189ff0188241a.pdf?index=true
- https://a19d597f-2220-41b3-9459-688249e8a20b.filesusr.com/ugd/f19f53_9577bffc2d8e47efbe331a190d73d7e4.pdf?index=true
- https://6205d428-d5dc-494e-bbc3-e2236f9d811e.filesusr.com/ugd/6885a6_883b83c1ed5f4505828cae0fbd2ea059.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fbca.bin8195fcd7357bdf5c5a601dd4c6929ce2918e7d49f7d70ecbf706b4032578b997 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFBCA | 5100 bytes |
font_01_sfnt_off00010cfb.binc52bc8c1014821f3b87af00abb5e4a37eb67c23d843d6a25bfdab1a5bb631bf4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10CFB | 10928 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.