MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many pointing to Weebly-hosted PDFs, suggesting a link farm or redirection mechanism. The heuristic 'PDF_SEO_LINK_FARM' and the presence of multiple external URIs indicate a malicious intent to direct users to potentially harmful content. The ClamAV detection and ML classifier further support its malicious nature, likely as a phishing or malware distribution tool.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jottigo.ru/123?utm_term=bachelor+degree+in+information+technology+courses
- https://nabebumiz.weebly.com/uploads/1/3/1/4/131452902/bupinaresatomor.pdf
- https://nudijezomuxu.weebly.com/uploads/1/3/4/3/134377325/vovopotusox.pdf
- https://xebikazogede.weebly.com/uploads/1/3/2/7/132740990/39993515c62a0e.pdf
- https://kagesurofuzesik.weebly.com/uploads/1/3/5/3/135303772/terazigusurusiroruf.pdf
- https://cdn-cms.f-static.net/uploads/4478664/normal_604f65ad300fd.pdf
- https://cdn-cms.f-static.net/uploads/4498330/normal_601cbab45d9c1.pdf
- https://cdn-cms.f-static.net/uploads/4401525/normal_606d4c07b7faf.pdf
- https://wutiboduselojo.weebly.com/uploads/1/3/4/6/134665342/waribat_dovedem_rifugafiwejov_tadoju.pdf
- https://lijasefevofik.weebly.com/uploads/1/3/4/8/134889997/295784.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://dojejezo.pbworks.com/f/52803408272.pdf
- https://uploads.strikinglycdn.com/files/a165f0ae-78ef-4c0a-93db-1223eab51ca4/40278015193.pdf
- https://uploads.strikinglycdn.com/files/dc03ed74-4154-41ed-8ff1-b2ae0debeb21/fifadetoji.pdf
- https://uploads.strikinglycdn.com/files/07f05339-7135-443f-96ca-1beceb747ce5/xidabasujisizu.pdf
- https://uploads.strikinglycdn.com/files/b184f693-42e5-47ef-9d94-0c09a5ee96e8/computer_programming_job_degree.pdf
- https://uploads.strikinglycdn.com/files/f50e8723-d125-42bb-9df6-4ff0370c01e1/probability_book_for_bsc.pdf
- https://uploads.strikinglycdn.com/files/6aeeb091-ee6c-4201-b427-82d0212e61a1/kabesuz.pdf
- http://metudebebi.pbworks.com/f/xulalabogubu.pdf
- http://kolasotosexu.pbworks.com/w/file/fetch/144415323/fivatigadir.pdf
- https://uploads.strikinglycdn.com/files/fa9f7a8f-e6db-4d74-a666-8527cbc59197/miwopekudajimal.pdf
- https://uploads.strikinglycdn.com/files/aa7ca158-d9ac-40f3-9471-49dc925e0f7a/rational_numbers_word_problems_worksheet_grade_7_with_answers.pdf
- https://uploads.strikinglycdn.com/files/9482a456-d228-40ef-8bb0-eea9244e9008/jebonovemetuligepolobis.pdf
- http://morabef.pbworks.com/f/wujidubezupotewonutixufe.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eae8.bin77cf5b37e0447a59d7f484cb30398334055f593cb00c50ca671716d03829360f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEAE8 | 5584 bytes |
font_01_sfnt_off0000fdc9.binfa3d7475a0f4a6b631976e674af1f34468210964dfe89f75bf2c0607104f35d3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFDC9 | 11300 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.