MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified as a link farm, with one primary malicious URL being https://xezojetit.ru/wix?keyword=tv+guide+yakima. ClamAV and ML classifiers strongly indicate this PDF is malicious, likely a phishing or SEO poisoning attempt. No scripts were extracted, but the PDF structure itself facilitates the malicious redirection.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/wix?keyword=tv+guide+yakima
- https://cdn-cms.f-static.net/uploads/4451757/normal_60451348ba0c0.pdf
- https://cdn-cms.f-static.net/uploads/4375908/normal_5fdc2875ce0a5.pdf
- https://cdn-cms.f-static.net/uploads/4426972/normal_6030aa7a280f8.pdf
- http://siondez.ru/nutrition_in_pregnancygi7db.pdf
- https://static.s123-cdn-static.com/uploads/4383444/normal_5feb81dd14b2a.pdf
- http://cashtanks.fun/zutesidarilosovuvutgh4o5.pdf
- http://vikiduxa.mywebcommunity.org/what_type_of_oil_does_lexus_rx_350_use.pdf
- https://cdn-cms.f-static.net/uploads/4410190/normal_5fd15327c981f.pdf
- https://static.s123-cdn-static.com/uploads/4469634/normal_5feb77ee8855b.pdf
- http://vibemezanolex.mypressonline.com/compuestos_azoicos.pdf
- https://cdn-cms.f-static.net/uploads/4368500/normal_602c8280c1ce0.pdf
- https://static.s123-cdn-static.com/uploads/4421466/normal_5fccf62ac8fd2.pdf
- http://tricitysikhs.com/encyclopedia_of_wine_beer_and_spiritsalios.pdf
- http://itsamorem.com/chander_pahar_story_in_bengali_free_downloade53bb.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://1639490a-f715-481e-9fb1-af38d332269b.filesusr.com/ugd/a59130_4fd2963af55d4e6aafbfa9184e445075.pdf?index=true
- https://1423d76f-a56f-4481-bf87-726e17039346.filesusr.com/ugd/14aee2_e83b62452d34491da9d4d3f5e566df2a.pdf?index=true
- https://2ddc7431-ff91-46e9-9708-195efd6cc195.filesusr.com/ugd/ffe0d3_f5e2c114e37147c7aff72db1e5dc3fe4.pdf?index=true
- https://uploads.strikinglycdn.com/files/52bbf9cb-0a2d-4c63-8503-6528880b6325/netgear_wndr3700v2_repeater.pdf
- https://uploads.strikinglycdn.com/files/20d1d99b-f13d-4d46-a692-eff07c505e9c/taxemiwigu.pdf
- https://e7e1611e-f78d-4dfd-b5ce-3be5f579732f.filesusr.com/ugd/4b76a6_967e08b96bcc4b11b9474514c6d47bc1.pdf?index=true
- https://uploads.strikinglycdn.com/files/f4e523bd-4dcc-4be9-b725-2b838c3b853e/toro_gas_trimmer_carburetor.pdf
- https://538d8494-0c7d-401a-b890-0485f6bc7bca.filesusr.com/ugd/29c71c_47f1006f0bca46c69904458ba21563e9.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00019128.binbbb8721918b74c6a276fe0c8a2533373279f9de40deb513b33156a65779c9326 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19128 | 5012 bytes |
font_01_sfnt_off0001a23d.bina363647f7f65ea3a259eb952dce91125702e0029cf15ddce8c5588d3e596f60c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A23D | 12208 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.