MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a significant number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. The primary URL, 'https://jumiwimov.ru/wix?keyword=imponte+phoenix+gta+online', suggests a lure related to online gaming. The presence of numerous Weebly and sqhk.co hosted PDFs indicates a coordinated effort to distribute content, likely malicious, through a link farm strategy. ClamAV detection and ML classification further support its malicious nature.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/wix?keyword=imponte+phoenix+gta+online
- https://saxipapes.weebly.com/uploads/1/3/0/7/130738636/mikekat-zifoxiko-sekaw-kazoboramin.pdf
- https://cdn.sqhk.co/dukapudubi/Yz5xAvV/95609473112.pdf
- https://cdn.sqhk.co/vesagivara/cL7BI40/bollywood_ringtone_2019_free_download.pdf
- https://cdn.sqhk.co/letarezetap/CKsihKb/40504930244.pdf
- https://cdn.sqhk.co/kitaparek/ijhj77S/super_sniper_650.pdf
- https://cdn.sqhk.co/sewuvavimebi/dhfagdu/30792087942.pdf
- https://cdn.sqhk.co/tazakabebilo/5hhiePk/10880573949.pdf
- https://cdn.sqhk.co/xorilulog/chfhbAq/ted_danson_tv_shows_becker.pdf
- http://sotarebesowula.medianewsonline.com/riditaduwil.pdf
- https://cdn.sqhk.co/gotakavapu/jfRVhaK/xizerafalimibezimix.pdf
- https://cdn.sqhk.co/miweguzeg/ihmhcXd/1mobile_market_app_apk_free.pdf
- https://cdn.sqhk.co/majumoros/cWQqjex/jatidisafotesedudoxodo.pdf
- https://cdn.sqhk.co/kutajanode/Uhi2xm2/puwega.pdf
- https://cdn.sqhk.co/tumosirewuw/idihthb/never_have_i_ever_cast_paxton_sister.pdf
- https://cdn.sqhk.co/nasanoroge/dClvjaA/lonewolf_zombie_fps_3ds.pdf
- https://cdn.sqhk.co/zupodejadofe/dhiTjje/vademututikoxavufi.pdf
- https://sezalufuveded.weebly.com/uploads/1/3/4/3/134389043/dufitugazibatinu.pdf
- http://gajonedorebuko.mywebcommunity.org/13179758743.pdf
- https://cdn.sqhk.co/kajipazuto/hekTwsE/super_bomberman_5_rom_europe.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/6e2c8672-304a-432a-b5ca-5092b679b993/lufelasina.pdf
- https://uploads.strikinglycdn.com/files/c33a71ee-ca17-48dd-9b0a-662fe91f5450/wings_of_fire_dragon_drawings_easy.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f3f4.bind8079d2a40c7ffe8528ee42e76afc3f1c30dc1b8ef07c1b95f695895b06b4bf3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF3F4 | 4964 bytes |
font_01_sfnt_off000104bf.bin063ad4d1e2d7bca68627bcc24b7ece0e50aefe1d58e25fdb430448196e6962d2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x104BF | 11792 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.