MALICIOUS
194
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=eragon+full+movie+in+hindi+free+download+300mb PDF link annotation
- http://spainwow.pro/lyrics_brown_skin_girl_by_wizkiduaxvh.pdfIn PDF document text
- https://nijasofefovo.weebly.com/uploads/1/3/4/7/134719995/wevaxale.pdfIn PDF document text
- https://tonawonigavima.weebly.com/uploads/1/3/5/3/135345065/3070982.pdfIn PDF document text
- http://arfesopt.com/desierto_informacion_en_inglesjlmuf.pdfIn PDF document text
- https://jevezorubik.weebly.com/uploads/1/3/4/8/134864628/5fa74fcde3ce03.pdfIn PDF document text
- http://believes.space/oxydorduction_exercices_corrigs_bac_projb6c5.pdfIn PDF document text
- http://itdomen.fun/teacher_quality_standardsipzpo.pdfIn PDF document text
- https://ditoleruv.weebly.com/uploads/1/3/5/3/135345680/rugujegikaxizi-sodidonixetefif-firozawesar-xuxamofovolako.pdfIn PDF document text
- http://copyrightshelpcenter.com/how_to_call_forward_att_landlinefn5g8.pdfIn PDF document text
- https://satuvimafinob.weebly.com/uploads/1/3/0/7/130739393/4936041.pdfIn PDF document text
- http://antileqphh.site/sevuxodi2lqn7.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/491adbb9-b0dd-4bda-bc92-96404169aef7/senco_nail_gun_repair_baton_rouge.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/902b7831-1c3b-4ae9-9945-48f64155299d/lg_top_loader_washing_machine_instruction_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8fe4311c-36dc-464b-b0f3-28988af0fd64/delta_table_saw_router_extension_wing.pdfIn PDF document text
- https://0fe83ef2-ed6b-4f04-a52d-31fe3c58d8d1.filesusr.com/ugd/ade4e6_fda73653835b48b0aa3c09cdc196377a.pdf?index=trueIn PDF document text
- https://e691ad07-92dc-45fa-af10-8929b4045ede.filesusr.com/ugd/87b9a8_007e0a7ae48143bebe2372f15c7095b0.pdf?index=trueIn PDF document text
- https://5e1449e8-5ae4-4a15-bc7a-ee23795bc964.filesusr.com/ugd/3a34a5_3ae3479d8ee741e79f04127cfecc14bb.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/8c18bd78-f55e-4be0-8b3e-e149d47a0f00/xavezezivumupazujivu.pdfIn PDF document text
- https://c788b29d-df2d-4d46-9946-349e8cce89b7.filesusr.com/ugd/a9e086_365f09816725493bab8c121c35ad0db4.pdf?index=trueIn PDF document text
- https://02bc4616-4eae-4b38-b2c9-0e654f754ee0.filesusr.com/ugd/069df5_6c94d98345144833a593a5c4fc2fbf5c.pdf?index=trueIn PDF document text
- https://31c8a3d4-0132-49f1-a04f-09c79d03e01f.filesusr.com/ugd/a4da84_f600f6c75c8b4b85b4ffd2da31c076e9.pdf?index=trueIn PDF document text
- https://8e8ef6ac-913c-489f-8395-c30730e7ba0a.filesusr.com/ugd/f39c52_bdd52728d81544918acd592d9dbf593b.pdf?index=trueIn PDF document text
- https://44dd6259-7513-41c7-b2f1-b2b1fc385d2e.filesusr.com/ugd/63022f_e019b4adda964ee8a4729ba64dcdf82a.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/0898b47c-0c97-448b-a343-0af04a10d7f9/timilufuzibupuxanazupaga.pdfIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ecaf.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xECAF | 5696 bytes |
SHA-256: d4ad6b23317e73b8fef6639012d83d5baee7498a03f86e21906f94276f78c3a9 |
|||
font_01_sfnt_off00010001.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10001 | 10584 bytes |
SHA-256: 90f253c52181a5a882df367cee3317490baf9bb06254d43a2f24f9ad086fad4a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.