MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which point to domains that appear to be part of a link farm, as indicated by the PDF_SEO_LINK_FARM heuristic. The document body, though heavily obfuscated, suggests a lure related to search queries. The presence of ClamAV detection and ML flagging further supports its malicious nature, likely as a phishing or spam distribution tool.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/strik?utm_term=que+significa+conclusi%25C3%25B3n+en+un+trabajo+escrito
- http://chunyoo.com/xoluburerawilepuripowud28bj.pdf
- https://xapotitiguwux.weebly.com/uploads/1/3/4/6/134668809/nesutipuzimub-tedodefoza.pdf
- http://optarfes.com/2012_jeep_grand_cherokee_headlight_ballast_replacement0jde7.pdf
- http://mklhhhh.space/nursing_diagnosis_list_for_pregnancythnpd.pdf
- http://appeal-ig.com/maus_google_drive_booksq59ch.pdf
- https://belafawejogawol.weebly.com/uploads/1/3/4/5/134583754/8032237.pdf
- https://vuwibisi.weebly.com/uploads/1/3/1/8/131856279/5170914.pdf
- http://profyhouse.ru/pre_lab_report_example_chemistry5wj9q.pdf
- http://madewithsunshine.com/what_are_the_factors_that_affect_motivation_in_second_language_learningdt8jg.pdf
- http://lastmarkt.ru/gexovevavegabq07lt.pdf
- http://ceter.xyz/lisinemirawiderilimufonal4lf5.pdf
- https://dodapoxole.weebly.com/uploads/1/3/1/3/131398067/613781ee261bae6.pdf
- https://vagomonezupu.weebly.com/uploads/1/3/4/4/134403629/redafumijipaxe-tewarituk-fosimatinuxa.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/9d188246-a2d9-419c-b481-350ea9ffcb0f/73405987582.pdf
- https://uploads.strikinglycdn.com/files/2e5f2399-6665-47ac-b368-51480df83a23/46072167428.pdf
- https://uploads.strikinglycdn.com/files/3990086c-244a-4b3f-8fb5-26671f13db11/no_game_no_life_season_2_episode_1_release_date.pdf
- https://eeeff038-21f9-42a6-bde0-cd945221d618.filesusr.com/ugd/9dc459_465c1d149173447dac377346809240e8.pdf?index=true
- https://uploads.strikinglycdn.com/files/208a2665-fcdb-40dc-ae9d-6ca1478e9f73/are_recaro_car_seats_safe.pdf
- https://uploads.strikinglycdn.com/files/2fe40c99-aa76-4d6a-ad9b-1cc7d38447a1/bushnell_telescope_voyager_78-9930.pdf
- https://141ebdc9-a3c9-4c6d-b8f9-366dbf139dec.filesusr.com/ugd/46bfb0_2552e385d174430da83ca79a728fe4ba.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011693.bin0bd995ca3f350a1f2f54ab5843ce979646fb60c148eb41d3fbf504356c35e58a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11693 | 5344 bytes |
font_01_sfnt_off00012891.bin4cdf6849a89cb36af988b76a710788b002ddd3e3a7b07888bade514c21b33d1e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12891 | 13140 bytes |
font_02_sfnt_off00015386.binf74ea1b10856a41706530bdcdc8b9c8cfad202a966f9a63c6c46aee3a92aa604 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15386 | 16464 bytes |
font_03_sfnt_off000169bd.binb50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x169BD | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.