MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
This PDF sample was identified as malicious by multiple heuristics, including a critical ClamAV detection and an ML classifier. It functions as a link farm, containing numerous external URIs, with a significant number of these pointing to disposable or potentially malicious domains. The primary purpose appears to be SEO spam or redirecting users to potentially harmful content, rather than executing a direct exploit.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/strik?utm_term=used+craftsman+riding+mower+parts+near+me
- https://nizedavigo.weebly.com/uploads/1/3/4/8/134879015/bcef876c066213c.pdf
- http://xiwakaravivomik.scienceontheweb.net/how_to_reset_aprilaire_wifi_thermostat.pdf
- http://lipuwisapi.mywebcommunity.org/encyclopedia_judaica_vol_19.pdf
- http://7gusevshop.website/my_talking_tom_friends_download_hackty82f.pdf
- https://vilavabakawo.weebly.com/uploads/1/3/1/6/131607043/7269062.pdf
- http://woxuruko.medianewsonline.com/synonyms_and_antonyms_worksheets_for_3rd_graders.pdf
- http://stroymarketmetal.ru/how_do_you_air_fry_french_fries_in_a_convection_ovenwcjuh.pdf
- http://austritkfa.com/adobe_flash_player_11._5_offlinertjfa.pdf
- http://lazategomid.scienceontheweb.net/gagapu.pdf
- https://najijufo.weebly.com/uploads/1/3/4/7/134714833/8798645.pdf
- https://rilavowa.weebly.com/uploads/1/3/2/7/132740415/jigoku.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/tajimipojimo/fitbit_versa_lite_not_showing_notifications.pdf
- https://88966db1-4a83-4446-b941-f65022a6235f.filesusr.com/ugd/928e0f_28b53164a9084b9fb773caad15a825d5.pdf?index=true
- https://cda84be5-0c54-4c05-8389-97bb004c798d.filesusr.com/ugd/fa9f00_adc4433aacbd4854959d8011520bb970.pdf?index=true
- https://s3.amazonaws.com/memobofilenabon/beginners_guide_to_social_media_platforms.pdf
- https://e8f98835-b194-42a5-b43f-fe2f29920dd6.filesusr.com/ugd/bf650e_d8f2aeded3fb455a98baa186ae6adbc9.pdf?index=true
- https://s3.amazonaws.com/pogolo/4622589768.pdf
- https://s3.amazonaws.com/rerinago/tatituzagadujipitazosu.pdf
- https://b5d51143-f34a-4a4f-9265-6917490cb775.filesusr.com/ugd/9f69bd_96b825baef9843f2ac15cc62e3ad9f98.pdf?index=true
- https://80cb706b-a9cc-40e6-9cd2-ad5688d6c4a8.filesusr.com/ugd/c84a73_01d2a5e0883d42eda31b106eaea8867d.pdf?index=true
- https://d6236f05-450e-4b96-9875-1783d83c708b.filesusr.com/ugd/912de2_86ca8d2a62e64379af291e1b40e15b66.pdf?index=true
- https://2f2ab42d-e0b4-4bd3-aa50-2430da1ff5fc.filesusr.com/ugd/eaf48f_691726e24ea64c06aeae78850cdf196d.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f701.bin67df27a4c3d49c5352ee722cf434b12750d9b1e6ea33de6289b87fea8c2162c6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF701 | 5528 bytes |
font_01_sfnt_off000109cc.binbc7dc3fa4ebd8cdaa5499b8ffd252dffe1fb140fb32be86ef9b3cf084e762d88 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x109CC | 10616 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.