MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The file is a PDF that contains a large number of external links, many of which are to other PDFs, suggesting a link farm or phishing attempt. ClamAV detected it as Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0, and an ML classifier also flagged it as malicious. The document body, though heavily obfuscated, contains text related to 'color matching worksheets for kindergarten', indicating a lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafficel.ru/aws?utm_term=color+matching+worksheets+for+kindergarten PDF link annotation
- https://kawijidaxo.weebly.com/uploads/1/3/4/8/134891868/kubemevibelube.pdfIn PDF document text
- https://wimelavejitovuv.weebly.com/uploads/1/3/4/5/134597731/nobejakasopozapuz.pdfIn PDF document text
- https://bubixoduxufito.weebly.com/uploads/1/3/1/0/131070588/adc52752fec1d35.pdfIn PDF document text
- https://kirimanadawa.weebly.com/uploads/1/3/4/3/134383910/4f5e23.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://static1.squarespace.com/static/5fc370a42cf09257bd7c0e07/t/5fc487716457125654ccb84b/1606715250280/pojodelivepamujigokufaj.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc77ace717a0f60c4039b47/t/5fcfe7371ce5cc3a1103a765/1607460664365/89449742125.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc5cbbe104edf1d77a2c1c8/t/5fcb4b848dcc5603bef1dc1f/1607158662726/zukovenuk.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc5d30b7848ba205d3a93a9/t/5fd601a15b1f6f7539cccfba/1607860642177/xitoralibewegofinagir.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7f44fdac-30b8-411c-ad6b-da5921a5e7a1/75803949732.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc77c63f59f035d0ccd600e/t/5fce0f9e74a40730fbbfa802/1607339935462/93609398520.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc64bd1be9b6939512f98cc/t/5fc702dba3696915e21a4154/1606877917680/hangman_movie_2017_ending_explained.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c2c86b28-19dc-4661-82ff-d289ab1289b8/warrior_goddess_training_workbook.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc144dc68612547ed60a5eb/t/5fd1b15eac13f65f6612288c/1607577951747/zinefixev.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc1beaab8467722f1da3b48/t/5fc5e6034f98375720aaf242/1606804996189/divijobasotugalemolozev.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000db0d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDB0D | 5404 bytes |
SHA-256: a8aaaf8cd5fdddc36c9dff88c5511bdb13d60f3d10daad9cc0bdfef48345fe29 |
|||
font_01_sfnt_off0000ed52.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED52 | 10560 bytes |
SHA-256: 63e82a4d747e24a60e2d1b3b6e1d87a3596f0ddaba006d0914c7495f5f11b8a2 |
|||
font_02_sfnt_off00011132.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11132 | 4324 bytes |
SHA-256: d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.