MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/wix?keyword=unicellular+organisms+and+multicellular+organisms PDF link annotation
- http://giftcard-sale.store/how_to_write_videography_business_plan_for_restaurantk12wl.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4408983/normal_5ff25c0f8c6f6.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4485153/normal_5ffb2345ea293.pdfIn PDF document text
- https://dijafujuzu.weebly.com/uploads/1/3/4/3/134369935/fajerodipizeni.pdfIn PDF document text
- http://damvglaz0.xyz/778563722297p3uf.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4455380/normal_602ca265dbb88.pdfIn PDF document text
- http://aviabileti.ru/behance_fonts_free3gkj7.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4388276/normal_603201f3e38c2.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4500186/normal_601ec6ff608f7.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4415745/normal_603a8304392f8.pdfIn PDF document text
- https://nibolujadi.weebly.com/uploads/1/3/1/3/131381302/2bb12.pdfIn PDF document text
- http://bullbananavannaone.xyz/1769-l33er_battery_faultsyksz.pdfIn PDF document text
- https://xefulexemifin.weebly.com/uploads/1/3/1/3/131398452/nitedesavonarininufi.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4368471/normal_6052f69bac46f.pdfIn PDF document text
- https://fakibugopozap.weebly.com/uploads/1/3/2/7/132712115/580089.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/f53dc14d-9e17-464f-8822-c0cbfc5653dc/palupatowoxi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/16638e45-ad2b-4852-b7af-c8c9085f3537/how_much_is_a_service_at_vw_garage.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6a148310-315f-4f7f-b9c8-549105067bcf/golunasopalitazij.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6390f969-e374-431e-b9ab-92380429e819/kudiwexavaminuxokokakifup.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/87ed8eef-ad43-4733-9655-d50c6fe486de/citi_bank_credit_card_payment_bill_desk_india.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1639c726-3bac-4a1e-8163-5bf1b36ac8f6/five_minute_mysteries_radio_scripts.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/34c481e2-b61a-4524-bd99-abf09433b407/19840159190.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/28c97536-6a2f-4a97-9f16-a50918b2f58d/introduccion_sobre_el_presupuesto_de_capital.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0735915a-2575-44fa-9111-4a95801900ea/norse_gods_names_and_meanings.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4773c936-de53-4978-9e39-1b30cc2a2a5b/the_giver_test_questions_and_answers.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f31f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF31F | 5252 bytes |
SHA-256: f3c9399e597f3ea34e3b347a3fd43bcaa31baae9d4d7825bcf0282ebdad1eb12 |
|||
font_01_sfnt_off000104e4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x104E4 | 10556 bytes |
SHA-256: d134b356d90c36cf7ab8fca70c246ea32312db8a14b7bc33f4e9923927ab09fd |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.