MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a phishing or trojan threat. It contains numerous embedded URLs, with a primary focus on luring users to 'cructi.ru' under the guise of a music downloader. The PDF's structure and the presence of external links suggest it's designed to redirect users to potentially harmful sites, aligning with phishing or malware distribution tactics.
Machine Learning
- Nyx PDF Classifier malicious score 0.9954
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cructi.ru/pbw?utm_term=tubidy+app+music+downloader PDF link annotation
- https://jurivulanikep.weebly.com/uploads/1/3/4/5/134525456/jedituw-ziwovadesig-paxejapujemub-nezowasedanu.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4405922/normal_6060fa6c55bd4.pdfIn PDF document text
- https://wunaramalus.weebly.com/uploads/1/3/4/5/134576193/7453352.pdfIn PDF document text
- https://josusijino.weebly.com/uploads/1/3/0/7/130739082/dolewik.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4483335/normal_6019ca6601b4c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4425933/normal_605302115e8d5.pdfIn PDF document text
- https://kiruxujekan.weebly.com/uploads/1/3/2/7/132740547/8f74ccf93f938a0.pdfIn PDF document text
- https://bigamurutixigi.weebly.com/uploads/1/3/4/4/134481126/fivanixevavobef.pdfIn PDF document text
- https://fapudunaga.weebly.com/uploads/1/3/0/7/130776769/93508.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4448536/normal_604d7f15d397e.pdfIn PDF document text
- https://vazejaxos.weebly.com/uploads/1/3/1/3/131382607/guvepigiwopaxoz_bamuwupazix_balap.pdfIn PDF document text
- https://nuniladolu.weebly.com/uploads/1/3/0/7/130775245/didimarijedago.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369920/normal_606dd65944eab.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://uploads.strikinglycdn.com/files/1ef65d4a-82b4-4853-abbb-c3a685c00daa/waxirinuxenilaxa.pdfIn PDF document text
- http://pebenuziwi.pbworks.com/w/file/fetch/144546696/pretest_biochemistry_5th_edition.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dba23b45-4ca8-4953-a1f8-892a2acba244/how_to_get_free_gems_in_brawl_stars_2019_no_human_verification.pdfIn PDF document text
- http://zuvevetub.pbworks.com/f/all_of_me_john_legend_sheet_music_easy.pdfIn PDF document text
- http://bofamawetodo.pbworks.com/f/assamese_movie_ratnakar_video.pdfIn PDF document text
- http://siseraxoru.pbworks.com/f/bwv_1007_allemande_guitar.pdfIn PDF document text
- http://lonazetubuz.pbworks.com/w/file/fetch/144675462/filmywap_bollywood_movies_2019_default.pdfIn PDF document text
- http://zajozote.pbworks.com/w/file/fetch/144977223/44202539780.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/185a8068-33a6-4332-82e9-018e9fb5d6cf/15670963543.pdfIn PDF document text
- http://vugufosenene.pbworks.com/f/dragon_ball_legends_mod_chrono_crystals_ios.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/37e4159a-4932-4f79-8939-c7c938d981a2/textes_transposs_picot_tome_1.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/da1414c0-6b6c-400b-868c-e94dc1def040/demusesufexorevufukosiw.pdfIn PDF document text
- http://supatibu.pbworks.com/w/file/fetch/144413841/korerijuroraragamasa.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f3cf.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF3CF | 5304 bytes |
SHA-256: c21260b9e3918fa1f4e365e7f5e23dabd7e8ffb1250bb6ff01d7a0b41e561e2e |
|||
font_01_sfnt_off000105bd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x105BD | 10500 bytes |
SHA-256: 09b6e71377a2ffcbbdd0dc536695cec50e0e8569de385b4c3bb2918b58c27013 |
|||
font_02_sfnt_off0001295f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1295F | 4324 bytes |
SHA-256: 1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.