MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was identified as malicious by ML classifiers and ClamAV, indicating a phishing or malware distribution attempt. It contains a large number of external links, suggesting it functions as a link farm to direct users to potentially harmful websites. The presence of embedded URLs and the heuristic 'PDF_SEO_LINK_FARM' strongly indicate a malicious intent to redirect users.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=sigma+1009+sts+manual+dansk PDF link annotation
- https://cdn-cms.f-static.net/uploads/4482208/normal_604db8b2455cf.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4499942/normal_5fe95b695fb74.pdfIn PDF document text
- https://ligiponofejejo.weebly.com/uploads/1/3/4/3/134346234/kimulelujalodizop.pdfIn PDF document text
- https://lelebozo.weebly.com/uploads/1/3/4/5/134578107/9ec65c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4420222/normal_60610b443e1ac.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4450345/normal_600efc69ce016.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4470389/normal_600f5f34861e9.pdfIn PDF document text
- http://zibodotuf.mygamesonline.org/arbitrary_constant_examples.pdfIn PDF document text
- http://bukuminuwakub.mypressonline.com/essential_calculus_early_transcendentals_1st_edition_solution_manual.pdfIn PDF document text
- http://lumapon.iblogger.org/76949162656.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://b32521b7-32ca-447e-9967-d27d0dce683d.filesusr.com/ugd/800b88_229e2d4def0844798c31a3e5421507bf.pdf?index=trueIn PDF document text
- https://849cba27-c1c2-4801-a47f-514a08c45c3c.filesusr.com/ugd/7f7a2c_e9ce81e471e845d8a64efe026dac0a6d.pdf?index=trueIn PDF document text
- http://jonimixe.rf.gd/73228343684.pdfIn PDF document text
- http://rovututuxopi.epizy.com/beethoven_5th_symphony_sheet_music_easy.pdfIn PDF document text
- https://0793e221-2e7e-4176-aae8-4ff4b75d8f7a.filesusr.com/ugd/64bd79_b69370e18d3947de99b6dfdfe5b017b3.pdf?index=trueIn PDF document text
- http://kariwukopufemu.rf.gd/fiwuzili.pdfIn PDF document text
- http://puredaw.rf.gd/kafiwoparexumokazotes.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000de8a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDE8A | 6616 bytes |
SHA-256: bb1a27f8f21f6956d775b74ded551e5b15dc7ddef551743f267c300d2dacf67d |
|||
font_01_sfnt_off0000f4f2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF4F2 | 5568 bytes |
SHA-256: cd8b8ecc0d566097131075d7e77c1e8d8c76c488a792564b1ee44503a5db380e |
|||
font_02_sfnt_off000107d0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x107D0 | 11776 bytes |
SHA-256: 89404c4661c91be8d8cc10282aafd363e09759a698202de757284847962dd079 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.