MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains heuristics indicating it is a phishing document and hosts a link farm of external PDF files. The embedded URL points to a domain that appears to be part of a phishing campaign, likely designed to trick users into believing they have a printer issue. The ML classifier and ClamAV detection strongly support the malicious nature of this file.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/strik?utm_term=hp+officejet+4500+false+paper+jam+error
- https://finudekenituw.weebly.com/uploads/1/3/6/0/136053274/951191.pdf
- https://sidanarud.weebly.com/uploads/1/3/0/9/130969336/sovujenatukod.pdf
- https://vifoluliguj.weebly.com/uploads/1/3/1/4/131437350/2305132.pdf
- https://muzunamarufo.weebly.com/uploads/1/3/4/4/134463020/fe6fc.pdf
- https://lelamibi.weebly.com/uploads/1/3/0/7/130738841/muvabasakazaluxej.pdf
- http://nizewapujapoj.22web.org/data_analytics_book.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/ff53ca74-28c0-4e87-b1b3-d00d9353b60a/medevigojulirodalob.pdf
- https://uploads.strikinglycdn.com/files/dee57f77-9bc0-4599-b27f-66ede5ba2b1c/29711791234.pdf
- http://riduxipilitaj.epizy.com/review_equifax_credit_report_again.pdf
- https://uploads.strikinglycdn.com/files/6534c139-511a-4be7-b6bf-7349ac7c7ade/junamalabomopupewatumo.pdf
- https://uploads.strikinglycdn.com/files/03dfbaba-ff7c-49cd-a122-1230d4fec1f9/how_to_get_a_cdl_in_oklahoma.pdf
- https://uploads.strikinglycdn.com/files/7c554e0e-2841-4d7f-b3fd-09a633398a36/piganelulalazafipag.pdf
- http://wibigaja.epizy.com/vufobusugafop.pdf
- https://uploads.strikinglycdn.com/files/b052ff62-cfaa-46e5-8011-f53830bde0db/canon_eos_rebel_t5i_charger.pdf
- https://uploads.strikinglycdn.com/files/d30e1124-27d0-410f-974e-5231d4383841/65749522359.pdf
- http://mepumubim.rf.gd/86825277301.pdf
- https://uploads.strikinglycdn.com/files/f3a5f1c1-c538-4545-a2bf-ad6c714b57dc/ribim.pdf
- http://pemeromerap.rf.gd/96991169660.pdf
- https://uploads.strikinglycdn.com/files/1b89792d-3005-4435-9849-2e540526eed3/mozoto.pdf
- http://duzesonugineku.rf.gd/reduce_smaller_size.pdf
- https://uploads.strikinglycdn.com/files/599466f4-ba0b-4595-9d05-529a8f4d57bc/xbox_live_gold_360_codes.pdf
- http://tifilumiteva.epizy.com/20282805598.pdf
- http://koziviwuvep.epizy.com/wubosipakafixadoxaf.pdf
- http://rinejifivazori.epizy.com/57750472517.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010155.bin973ce5316a4dbee86f77b94bf6dbc56b7d042535812dd37bbf338970cf9b5af6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10155 | 5232 bytes |
font_01_sfnt_off0001132b.bin2d3ad18987f2ab6b2c7982035d05f39be80fb455497bea463ff966b07b308378 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1132B | 11860 bytes |
font_02_sfnt_off00013b57.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13B57 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.