MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, a common tactic for phishing or distributing further malware. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as a phishing trojan. While no scripts were directly extracted, the PDF structure and embedded URIs suggest it's designed to redirect users to malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=technical+communication+strategies+for+today+pdf
- https://cdn.sqhk.co/wepenujofow/hdihUig/40839000181.pdf
- https://cdn.sqhk.co/xadakede/gp2tPnE/46543010424.pdf
- https://cdn.sqhk.co/binebelezux/chaigjb/jubaminarogiv.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/2b32b7a4-a15f-4586-9cde-2dfff31fc603/how_can_you_tell_if_conjunctivitis_is_viral_or_bacterial.pdf
- https://571cbd0a-ba82-408d-be6d-2df53a8fcfe5.filesusr.com/ugd/02af14_675efa5aaca342c49e7b794441917568.pdf?index=true
- https://5a4e7950-e122-4b3c-9cf7-894e7f5b1216.filesusr.com/ugd/76aeb6_6636ec91cca14504ab516fd6323822c1.pdf?index=true
- https://3ff4c494-4984-418a-b709-7a5c611cca0a.filesusr.com/ugd/adbee0_8a4f9bae4f8f42ddb897c2aec8e1729e.pdf?index=true
- https://044e8d80-c429-4a1f-820d-9b443c65b389.filesusr.com/ugd/53c654_b986988430144375a50696cf55e565e1.pdf?index=true
- http://nelodetasa.rf.gd/gmt_full_form_all.pdf
- https://2ddedb0e-b7b0-41c9-a8bc-c018bd0e6e4c.filesusr.com/ugd/70094d_ae75d4b0c1fe40b097d2e7d57f34dfa2.pdf?index=true
- https://a6f18165-9bfd-46c9-8f51-0ab50cd0b687.filesusr.com/ugd/265c7a_88b91df9178041f098ffaff4314156f6.pdf?index=true
- https://uploads.strikinglycdn.com/files/6386c9f1-9558-47a4-8292-5fdf7b36fa75/mudekevujipefanewu.pdf
- https://uploads.strikinglycdn.com/files/13f24c68-693d-4068-afe1-afc63cd8e090/dujujurefagipulef.pdf
- https://uploads.strikinglycdn.com/files/beca2188-75ef-440d-93eb-dd9c667492e1/java_programming_language_for_dummies.pdf
- https://uploads.strikinglycdn.com/files/d0697f9f-376b-4bef-8165-5552a1785307/gewutatoboporakudogix.pdf
- https://cee4a208-09ac-40e0-983f-4c2cc776acbe.filesusr.com/ugd/5ed537_b6c99f3b2e9947cbbd6d6994cf8a2abc.pdf?index=true
- https://c827806f-f9bf-4fd3-a4ce-e487c020fa79.filesusr.com/ugd/6fd45c_88a8d73849124a6b85b3db4dd4a3e9c4.pdf?index=true
- https://1a899ca6-11bf-4464-971e-4bf0b885e765.filesusr.com/ugd/4ac3ff_a06bf36f33104ca1af023fd5e74e6ce3.pdf?index=true
- https://uploads.strikinglycdn.com/files/d529a59b-1a12-43bf-8ee8-9faaeb1e4581/produplicator_warning_source_error.pdf
- https://uploads.strikinglycdn.com/files/d723c631-e0a9-4a9f-8293-57fb095f80d8/84856404310.pdf
- http://jizekoliwivutu.rf.gd/dotnet_interview_questions_and_answers_for_freshers.pdf
- https://uploads.strikinglycdn.com/files/a5a37139-850f-43db-8304-b02f0e01cb17/love_does_bob_goff_discussion_questions.pdf
- https://uploads.strikinglycdn.com/files/5749cfbb-d69b-42b7-9211-807f388149b0/how_to_report_income_change_for_food_stamps_in_pa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f796.bin07397bf621c5d57b956b417826c3affc6eaaa29469db9243c1397dd58de0881f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF796 | 5620 bytes |
font_01_sfnt_off00010a94.bine984e3b9fb7dfb7942969f4d64ff86836d87f2cf369efbf6c88faea24b51e0be |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10A94 | 10784 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.