MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains numerous external URIs, with a significant number pointing to disposable hosting, suggesting a link farm or phishing lure. The presence of embedded URLs and the overall structure strongly suggest it's designed to redirect users to potentially harmful websites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9979
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/wix?keyword=sam+to+bam+compression+ratio
- https://cdn.sqhk.co/sifalavuxozo/hageejh/baby_animal_coloring_pages.pdf
- http://gopusoduj.mygamesonline.org/siwivibewubutelok.pdf
- http://suvuxivenorum.mypressonline.com/hugh_ferriss_the_metropolis_of_tomorrow.pdf
- http://sowadegepixu.22web.org/unity_and_struggle_amilcar_cabral.pdf
- https://nagajaburelu.weebly.com/uploads/1/3/2/7/132740350/rowurug.pdf
- http://nemosixumeki.mypressonline.com/how_to_start_reading_spider_man.pdf
- https://cdn-cms.f-static.net/uploads/4489992/normal_5fd7add7b3da7.pdf
- https://jarowezib.weebly.com/uploads/1/3/0/8/130813985/9335f.pdf
- https://cdn.sqhk.co/nadizolobe/jd5d7gg/checksur._exe_windows_7_32bit.pdf
- https://cdn.sqhk.co/tuparesoxaj/Mg2Zhce/99592729477.pdf
- https://kivijakesav.weebly.com/uploads/1/3/2/7/132740669/bavawuziwijara-wibisupezolozuz.pdf
- https://cdn.sqhk.co/kanemili/gihcjhP/gisemufenidokavuvubux.pdf
- https://cdn.sqhk.co/gulifunanale/f9ahigf/winrar_64_bit_windows_10_pro.pdf
- https://cdn-cms.f-static.net/uploads/4365621/normal_60473a3085679.pdf
- https://jovinafunen.weebly.com/uploads/1/3/2/6/132695325/fagikex-dutuxewogixozos-tupewijukorola-nojuvuvobubajo.pdf
- https://cdn-cms.f-static.net/uploads/4393018/normal_60475f470d43b.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://lojubefogugiku.onlinewebshop.net/how_much_is_needed_to_start_forex_trading_in_south_africa.pdf
- https://uploads.strikinglycdn.com/files/fc94052a-62ad-44f4-aa08-3b8c234a43cd/84406062253.pdf
- http://gobofitis.epizy.com/league_of_legends_akali_rework_guide.pdf
- https://uploads.strikinglycdn.com/files/d33c5761-89e1-459a-8a4b-5acf26e0172b/final_fantasy_7_remake_trailer_2018.pdf
- http://xesupunugotim.rf.gd/96778566482.pdf
- http://nadiripu.epizy.com/xfinity_app_s_not_working.pdf
- http://misebupafavo.rf.gd/vpn_free_apk_best.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00015d6f.bin174f2990fd7e73fc16ec6a57b7388c7893866725bb12a691e46929197de55297 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15D6F | 5288 bytes |
font_01_sfnt_off00016f4f.bin8f3c46dee99a7592841fd3b2c86444a3ed21e8ed87a06c048485d7d3b60e6777 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16F4F | 11932 bytes |
font_02_sfnt_off00019767.binb316e4572f9e808cff83b1bbfd9809b53027153a2f86cf526450a064958e3b1a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19767 | 16280 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.