MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9967
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/strik?utm_term=is+draco+malfoy+in+love+with+harry+potter PDF link annotation
- http://numulul.mygamesonline.org/97008963560.pdfIn PDF document text
- http://rowowesofazov.medianewsonline.com/98053206689.pdfIn PDF document text
- http://italonewsero.site/where_to_watch_vanity_fair_uk8i4h1.pdfIn PDF document text
- http://fukazab.mywebcommunity.org/75092059970.pdfIn PDF document text
- http://siondez.ru/tirilirotaputibenusip83a.pdfIn PDF document text
- http://wonder-ita.fun/viwejenetotijupofikmujy5.pdfIn PDF document text
- http://nazhivy.net/a_field_guide_to_liesfczvf.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://51da6a7d-ee05-4a49-87ee-1b74af3aeb07.filesusr.com/ugd/b80405_7d384d436f75413e9b93f81b52a90a10.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/fifuto/tennessee_williams_night_of_the_iguana_poem.pdfIn PDF document text
- https://s3.amazonaws.com/ruzaganog/tusaxenojobobi.pdfIn PDF document text
- http://mojenuj.atwebpages.com/xefasoxakugu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4fbcb861-ad75-450d-9a46-942a8fa8477e/fugunadod.pdfIn PDF document text
- https://5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com/ugd/460efe_0d781e17f9724651a7fddd115e72da0e.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/sesijesule/pak_study_notes_for_ba_in_urdu.pdfIn PDF document text
- https://s3.amazonaws.com/fejififimaketo/the_four_functions_of_management_involved_in_rowe_include_all_of_the_following_except.pdfIn PDF document text
- https://d102a0f2-001f-4998-bb0a-88ac30ac05b5.filesusr.com/ugd/771ea4_5040474906544bcfa76c100d8b521be6.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/somisilegex/microscopic_hematuria_canadian_guidelines.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7272216e-faf0-4508-9b04-ae82ea19a43c/salulodesidorunud.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6bbf8995-2612-4d56-b546-7078a3bd113e/charter_cable_remote_control_troubleshooting.pdfIn PDF document text
- https://s3.amazonaws.com/paxunu/povubirasar.pdfIn PDF document text
- https://s3.amazonaws.com/joterige/78059414883.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ecd0f1f8-1676-4882-9d8a-4fdc041ae69a/how_much_does_it_cost_to_replace_engine_and_transmission_mounts.pdfIn PDF document text
- https://s3.amazonaws.com/negonanopix/welevemusosemadumonaf.pdfIn PDF document text
- https://7e8267f5-6380-480e-ad72-df526eaefc07.filesusr.com/ugd/cbe325_ecf209f8ef084535872f8002096ea4f0.pdf?index=trueIn PDF document text
- https://dd3a609d-fcd9-461e-ae06-f7e9ec6f332d.filesusr.com/ugd/811c3f_dde162894c46458eade9901c30f4b2b3.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/gezejoputiwinu/57411165565.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fb12.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFB12 | 5584 bytes |
SHA-256: cec2d13cf7fec15cfec62ffde2f7874cfa7a06c50b0892f6642505a9c8b43860 |
|||
font_01_sfnt_off00010e02.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10E02 | 10676 bytes |
SHA-256: 2ec2a3d7a4f2999f43166d921dd8fca5c78df3a20ae77cba1eefe6f097518064 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.