MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was identified as malicious by multiple heuristics, including ClamAV and an ML classifier, and contains a large number of external links. The primary malicious URL, https://pelibifir.ru/strik?utm_term=ti+ba+ii+plus+professional+vs+ti+ba+ii+plus, suggests a phishing or malware distribution attempt. The document body, though heavily obfuscated, contains metadata related to 'wkhtmltopdf' and a date, indicating it was likely generated programmatically to host these links.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/strik?utm_term=ti+ba+ii+plus+professional+vs+ti+ba+ii+plus
- https://fiziwiminika.weebly.com/uploads/1/3/4/6/134686918/bogababaxeva.pdf
- https://cdn.sqhk.co/defisepeniba/PngfVdF/ragdoll_soldiers_the_combat_warriors_game_schedule.pdf
- https://xisidugaboker.weebly.com/uploads/1/3/4/4/134436298/6849055.pdf
- https://cdn.sqhk.co/pusuvizodez/epsENk9/tofofogare.pdf
- https://cdn.sqhk.co/ravusigi/gdhhVb6/35949482494.pdf
- https://bezamefiparafu.weebly.com/uploads/1/3/4/6/134665790/xabufesozes_wodigemirule_lusopib.pdf
- https://cdn.sqhk.co/feduvefas/gcQbN2b/plantar_wart_or_corn_pictures.pdf
- https://cdn.sqhk.co/tezasevimab/Bogdvhb/boss_battle_games_unblocked.pdf
- https://zenozuniwilifa.weebly.com/uploads/1/3/4/1/134131556/latelopupewogabu.pdf
- https://cdn.sqhk.co/fuvebopeweb/D8hjihi/the_gunner_stickman_weapon_hero_mod.pdf
- https://xisofigutuf.weebly.com/uploads/1/3/0/7/130740477/6072386.pdf
- https://cdn.sqhk.co/soziwariru/NwjeOjG/jazanuv.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/d18925d0-4ce3-4194-bc0f-66464898eef7/muwoga.pdf
- https://uploads.strikinglycdn.com/files/a1c9556f-7efe-44fd-bf17-103b17039b02/jhumpa_lahiri_a_temporary_matter.pdf
- https://de461234-8179-4892-b46d-67dc01ae00af.filesusr.com/ugd/69bbc5_d0c90cb12a914c6bbad3392c78bc25ba.pdf?index=true
- https://4b5f4e46-8b81-4257-bf39-61fc08ba57b0.filesusr.com/ugd/7ea8bb_6395b69567a64579b32571c03be789ae.pdf?index=true
- https://s3.amazonaws.com/bubodeliza/cross_flow_heat_exchanger_experiment_lab_report.pdf
- https://uploads.strikinglycdn.com/files/2ad135b8-5fe2-47e2-a351-a81367873375/95599539010.pdf
- https://s3.amazonaws.com/zifilobesumafi/fofojoripupatolobemebotur.pdf
- https://e4fb9bf1-a3d6-4767-9bf2-2a1021e5dc09.filesusr.com/ugd/53cfc7_19a012154c58455ab10b2e7e9e414d54.pdf?index=true
- https://uploads.strikinglycdn.com/files/4cbbb171-9ef0-4aa4-a8a2-4a9b607011dc/diy_ar-15_mag_coupler.pdf
- https://c18d7360-3707-4bf1-9d6f-52ba7510fa17.filesusr.com/ugd/76cb06_63d3c262ace14ceab6b3a3bac43889dc.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f476.bin159acedad9d978cae9bfe038eaad3407835a89dc283836efc716e81efcbeccd8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF476 | 5044 bytes |
font_01_sfnt_off000105af.bin269104fe344301075bb373450fba23043a1abe236c48cc43b2b4bfb24336e162 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x105AF | 16156 bytes |
font_02_sfnt_off00013829.binbf8f9ece8d9d74ce2d7a98a07ee1bb8f4056faf702b3b1702118181e85f1b939 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13829 | 16312 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.