MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The PDF file was flagged by multiple heuristics as malicious, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. It contains a significant number of external links, indicating a link farm strategy to direct users to potentially malicious sites like 'pelibifir.ru' and 'magazinrf.xyz'. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/123?utm_term=barcode+scanner+android+google+play
- http://magazinrf.xyz/rtgs_form_of_allahabad_bank_in_formatgzg3t.pdf
- https://cdn.sqhk.co/zalivelo/hcpjbib/dosipexun.pdf
- https://cdn.sqhk.co/nojedajoze/njjsYhi/detention_pond_maintenance_cost.pdf
- https://cdn.sqhk.co/lovaxixifew/ijjLheP/view_booster_views_for_views_instagram.pdf
- http://idealslimitaly.site/32069568532qo0e0.pdf
- http://alteramaks.world/how_to_make_call_to_action_button_in_wordpresswexn8.pdf
- http://pasendapp.online/summary_writing_exercises_with_answers_igcsewe17l.pdf
- https://cdn.sqhk.co/rajexizeba/Iii2lhc/sabivalaxotajewemimepare.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/c193e81f-4329-4033-91bb-dc0979e882e7/58128941096.pdf
- https://e791dc30-71fd-4519-a75e-453748eb9c32.filesusr.com/ugd/8a5fcf_faa554e944e94ae5a4cdb066fd1832d2.pdf?index=true
- https://636e06b3-920c-4898-b827-ef778bbbc101.filesusr.com/ugd/40512e_3b26de2185474029b9831056efdf86f5.pdf?index=true
- https://b7eb3c74-9f10-4efd-a612-efb7ea03662f.filesusr.com/ugd/7198c1_351c21ce813049e6bf433335e49358d1.pdf?index=true
- https://uploads.strikinglycdn.com/files/5da5dba3-b523-4286-8315-a3a2c1aa5624/how_to_program_a_chamberlain_garage_door_opener_953estd.pdf
- https://s3.amazonaws.com/muvarelo/bram_stoker_dracula_film_1992.pdf
- https://3465328d-eb21-4af5-a94e-b8fdacefaafa.filesusr.com/ugd/c63bf9_1cba72a422da438ba950640bbb217fe5.pdf?index=true
- https://uploads.strikinglycdn.com/files/bacbc69e-a434-470d-ad09-7d8883d00061/cul_es_la_estructura_de_un_texto_narrativo.pdf
- https://2e03c77f-99cc-4591-9807-54d8d49c9ce6.filesusr.com/ugd/759733_bdcb6df470904ec5a2cd3f0c6300938e.pdf?index=true
- https://58552d80-c20c-4e4f-99b9-91bedbcc07a3.filesusr.com/ugd/c18496_ac07e96a27d74834bcc4b8081d80f6ca.pdf?index=true
- https://s3.amazonaws.com/kubafezin/13170979300.pdf
- https://ab60d57a-1f92-408f-9079-0b325776b613.filesusr.com/ugd/724fb5_4a13aa5c71a74f9eab580b519e6e61e0.pdf?index=true
- https://uploads.strikinglycdn.com/files/fad1299b-9ae4-43a8-90fb-b456a7fa33b3/how_to_sweet_talk_your_lover.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e3b8.bind5f1625346337d81dd11a828c63293c82626a364dcb26fc9f7fe47d763eebfeb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE3B8 | 5392 bytes |
font_01_sfnt_off0000f623.bin1a2d96c2c9bee9f8fd2fd899b12584a3bdeda132ed94865e594a987b8e2dad99 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF623 | 10828 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.