MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of external links, many of which are to other PDF files, suggesting a link farm or SEO manipulation tactic. One of the embedded URLs, 'https://huntic.ru/pbw?utm_term=diep.io+mod+apk+unlimited+points+1.2.10', appears to be a lure for a game mod, which is a common social engineering pretext. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://huntic.ru/pbw?utm_term=diep.io+mod+apk+unlimited+points+1.2.10
- https://ziwevanefenej.weebly.com/uploads/1/3/4/5/134591483/b82495e1a7f8.pdf
- https://cdn-cms.f-static.net/uploads/4477626/normal_602e9a7d19865.pdf
- https://cdn-cms.f-static.net/uploads/4421767/normal_602c8b499ce95.pdf
- https://wutosalix.weebly.com/uploads/1/3/4/6/134635680/7934829.pdf
- https://lusogovo.weebly.com/uploads/1/3/4/3/134358567/2672243.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/9a63dcab-e11c-4022-bde1-1e15a07eee0d/vatodut.pdf
- https://uploads.strikinglycdn.com/files/04db51fc-0a28-4139-a108-8be639cfc784/pisanogoziwonebewizenexik.pdf
- http://fuvesiwowegu.pbworks.com/f/supax.pdf
- http://xoxafepapesu.pbworks.com/w/file/fetch/144420369/vudosav.pdf
- https://uploads.strikinglycdn.com/files/09e41bd0-e2e2-4f22-8a20-4d19c4431b1a/lununusumuramogebet.pdf
- https://uploads.strikinglycdn.com/files/3597cb17-b351-4662-b2b7-d9004a4eb04e/28469143876.pdf
- https://uploads.strikinglycdn.com/files/be9c2839-e5a6-4831-81ae-2001f9642e4a/mizunuxosof.pdf
- http://masawumel.pbworks.com/w/file/fetch/144420612/waxoj.pdf
- https://uploads.strikinglycdn.com/files/2b1a619d-390e-4de8-88b8-cedf0d938cb7/46353225253.pdf
- http://xuruzinijub.pbworks.com/f/36049075581.pdf
- http://xuruzinijub.pbworks.com/f/valores_normales_de_amilasa_y_lipasa_serica.pdf
- https://uploads.strikinglycdn.com/files/15d3fa6b-1bc8-44f6-b0c2-506b2578c9f5/palmistry_reading_free_app.pdf
- http://kipizasuzeda.pbworks.com/f/jack_and_the_beanstalk_book.pdf
- http://poxanoralanu.pbworks.com/w/file/fetch/144422310/chinese_character_writing_practice_book.pdf
- http://tukufidanega.pbworks.com/w/file/fetch/144423096/43465779261.pdf
- https://uploads.strikinglycdn.com/files/ce6fb3c0-613c-4382-8ac1-8008e64a39cd/palomik.pdf
- https://uploads.strikinglycdn.com/files/dda45b2a-752e-4d61-b60a-bb9067e84d10/how_to_draw_cartoon.pdf
- https://uploads.strikinglycdn.com/files/12e7b091-1606-447e-af3c-3e1ac8fb52b1/vomamewano.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dcb8.bin921fa8af720103112915242f2e810b75518cba252fa330107cd9924d5ab66063 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDCB8 | 5428 bytes |
font_01_sfnt_off0000ef2e.bin4bca883e9d96d28afcda718e80c6207264aa3efab1877ea9f0e55ce22d852ade |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEF2E | 10604 bytes |
font_02_sfnt_off00011378.bina95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11378 | 16204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.