MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are dynamically generated or use numeric slugs, indicating a link farm for SEO manipulation. The ClamAV detection and ML classifier strongly suggest malicious intent, likely phishing or malware distribution. The embedded URL `https://bologen.ru/wix?keyword=pixel+chix+mall` is a primary indicator of the lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://bologen.ru/wix?keyword=pixel+chix+mall
- https://static.s123-cdn-static.com/uploads/4499317/normal_5fe4132f0f0ca.pdf
- https://cdn.sqhk.co/radojiga/6ifgchb/digital_marketing_strategy_implementation_and_practice_7th_edition.pdf
- http://gaydating.world/gowadorukejemnj9f.pdf
- http://cosmeteca.com/8930275214879a97.pdf
- https://cdn.sqhk.co/temegolu/iF1iagh/zogefobulilisorolupabebat.pdf
- https://cdn.sqhk.co/gabebutiz/gThd5Wc/96011952269.pdf
- https://cdn.sqhk.co/kalusoxat/2Uibpw3/foxovesabababififelazulov.pdf
- https://cdn.sqhk.co/wutalididow/ic2jghf/48764769748.pdf
- https://cdn-cms.f-static.net/uploads/4471250/normal_603fed4a16b23.pdf
- https://cdn-cms.f-static.net/uploads/4416140/normal_60503676efa6d.pdf
- http://nikaold.site/engineering_journal_article_templateqcj5j.pdf
- https://cdn-cms.f-static.net/uploads/4377125/normal_5fe6ff4b730be.pdf
- http://car-den.ru/sewab4j2ei.pdf
- https://cdn-cms.f-static.net/uploads/4470232/normal_6045d8e4ec0de.pdf
- https://cdn.sqhk.co/zuxedanafowa/0dJkhen/70280772316.pdf
- http://torchqbfl.fun/speed_calculator_mb_sswexb.pdf
- https://cdn.sqhk.co/rirexiwudag/2jaFhdl/super_brawl_universe_how_to_unlock_all_characters.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://769966b8-4adc-437e-bba8-f198cf6e171b.filesusr.com/ugd/41a0b6_61b2560149c64ce1ab3c7212d99cac8f.pdf?index=true
- http://sikofus.epizy.com/imu_cet_2019_online_form.pdf
- http://xevezowa.rf.gd/11185149736.pdf
- https://9e730ba1-499c-413e-9a09-8a81f8121270.filesusr.com/ugd/0a0016_ceed92e3170147caacb0c93a4ea27b07.pdf?index=true
- http://pupovedifa.rf.gd/portugues_sem_fronteiras_3.pdf
- http://rabijeno.epizy.com/ranemovavuzezubutuso.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e80f.bin66201da95c93b3f3763869fe84b5961dc2e11371a7314ba50b5ce9e7455ffaf4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE80F | 4836 bytes |
font_01_sfnt_off0000f85e.bindc38ece4b5489b0af8b9e5a83e227e91a5b68710ed08b9cd03995bedbe170e32 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF85E | 11760 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.