MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by multiple heuristics, including a high-confidence ML classifier and ClamAV, indicating malicious intent. The presence of numerous external URIs, many hosted on disposable domains, suggests a link farm designed to redirect users to malicious content. The document body, though partially corrupted, contains keywords related to PDF manipulation, reinforcing the lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/award?keyword=attach+pdf+files+together+online+free
- https://sakixori.weebly.com/uploads/1/3/3/9/133997256/jeropafimobu.pdf
- http://revujutipisan.22web.org/2511873250.pdf
- http://bupro.asia/how_to_express_happy_feelings_in_words2vtkx.pdf
- https://cdn-cms.f-static.net/uploads/4458389/normal_6055b714b0c27.pdf
- https://povefedonigo.weebly.com/uploads/1/3/1/6/131637150/4864534b10c69.pdf
- https://cdn-cms.f-static.net/uploads/4469634/normal_603da883eb12a.pdf
- http://myfavoritesun.xyz/girl_from_ipanema_lyrics_portuguese_translation90z1m.pdf
- https://cdn-cms.f-static.net/uploads/4485695/normal_5fdb904e80e58.pdf
- http://wejaduz.mypressonline.com/statistics_with_r_best_book.pdf
- https://meluwirukumipi.weebly.com/uploads/1/3/1/4/131483006/fakonosozu.pdf
- http://lnstagram-helping-centre.com/68064929197czvil.pdf
- http://vladmer.ru/pebevovipivexozow36ql.pdf
- https://fusagepewaliwe.weebly.com/uploads/1/3/5/3/135325652/75a9494a9f86.pdf
- http://wijofotezopadik.medianewsonline.com/22980177297.pdf
- http://anarchymedya.com/sejewunudbk7h6.pdf
- http://finansi-7.online/87837876249170jp.pdf
- http://xumupizaxuto.scienceontheweb.net/best_free_app_to_annotate_ipad.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- http://jimarol.myartsonline.com/56568383306.pdf
- http://mokunir.rf.gd/instrumentation_engineering_dictionary.pdf
- http://xinifaduzinuvu.onlinewebshop.net/muvidaponit.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ed36.bin39aff7da20fef760b676af77c6ab207ebf50d52baccb6aa0e093eeb371cfa699 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED36 | 5196 bytes |
font_01_sfnt_off0000fed6.bin4890c34f23773849049e6ee2f8db783a00d69b2d4bdcda34a25c0fd33d718d4e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFED6 | 10616 bytes |
font_02_sfnt_off00012334.bind1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12334 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.