MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with one pointing to a suspicious URL associated with phishing. ClamAV and ML classifiers flagged this PDF as malicious, specifically as a phishing trojan. The presence of embedded URLs and the overall structure suggest an attempt to redirect users to a malicious site, likely for credential harvesting or further payload delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=safe+haven+adt+hiring
- http://mists.space/modal_verbs_exercises_multiple_choice_with_answersyxsy2.pdf
- http://ellmax-site.xyz/xudotofahikuo.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/sesijesule/state_space_representation_in_controllable_canonical_form.pdf
- https://a9864912-ad24-422b-99f3-2d90f7703507.filesusr.com/ugd/d6af85_6fc95fb773894d5cbac067bd71adcceb.pdf?index=true
- https://73856814-13bb-4d44-aeaf-752cce6ba6bd.filesusr.com/ugd/a0d21a_2dfb5362a79a4f468eddc8e34c1a3a9a.pdf?index=true
- https://s3.amazonaws.com/tesapibebujep/angular_json_form_editor.pdf
- https://uploads.strikinglycdn.com/files/08332975-aa85-4758-9133-3a740bc57f57/77846179220.pdf
- https://s3.amazonaws.com/wipotegadodorek/bixew.pdf
- https://e1cf253b-b3af-4135-a675-1c3c021177f9.filesusr.com/ugd/111c46_2ded4935cd174dd78bd8895983b43ac5.pdf?index=true
- https://s3.amazonaws.com/takateg/alphabet_cursive_writing_free.pdf
- https://fc060a1e-8c1d-4b7d-bafd-75f79d4c6355.filesusr.com/ugd/c0a468_4bfd84c4b914448aafd30a7c120e94ee.pdf?index=true
- https://uploads.strikinglycdn.com/files/2bfb2698-af04-44b0-9f94-0b5273b910a7/61144340247.pdf
- https://748f1d53-d141-46c1-926a-d14fc69713a3.filesusr.com/ugd/e3ed1f_a96bbf58ee00401e8637b6c603751a0b.pdf?index=true
- https://24451074-f53b-4065-993c-779ba3957988.filesusr.com/ugd/0ae25f_ee3544a44c204b6598709c69f8fd5d15.pdf?index=true
- https://bcbc83ff-a82b-4234-bf1d-c69e8cae54d5.filesusr.com/ugd/057c82_424afb98de7f467481a8937f3f2c8587.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fe9a.binca0fef01f9c54a533bb159b2bc359dc625cc2964012f2ace5a304b3101828f2a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE9A | 5120 bytes |
font_01_sfnt_off00011002.bin64a0bbed4904ef6d3dc0d2caa69355f2bf384e0b92a09e472356ba82028dc329 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11002 | 4700 bytes |
font_02_sfnt_off0001218e.bin0d07a51493d35d4210c7a48b1f94b48109f646964eda1fe2ea78883e4da369e5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1218E | 11612 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.