MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dafemum.ru/strik?utm_term=arduino+ide+user+manual+pdf PDF link annotation
- https://cdn-cms.f-static.net/uploads/4365563/normal_605404db5509a.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4374521/normal_5fffeca4e9e08.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4465018/normal_6028106c9f495.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4450415/normal_5feb74f37f2a3.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/befarekogol/xovem.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/865bd9d8-aec7-417b-88c5-1a955f0fa6a8/52396588144.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9e3726ec-0f7f-49a9-93b7-3b6616e86ddf/todakifapozabidep.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/da9b4feb-48cb-422f-aef4-4cadcdf35775/sjcam_sj4000_air_4k_wifi_aksiyon_kameras.pdfIn PDF document text
- https://67d298e0-85f4-4ad4-bf36-e1ac857e42fc.filesusr.com/ugd/b6bf5b_4216477153d84ff1b62f63a7203933f2.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/c6a69306-75f9-4ab8-9953-d1dbae531ddb/nairobi_central_sda_church_live_stream_today.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ade1b68e-1eb0-4812-ba0e-974b27800a8d/broken_vessels_amazing_grace_hillsong_acoustic_guitar_chords.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/70130ae7-dbf1-4544-9e37-dcc77cc443f7/semujaz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bfc1673c-2d24-4984-986b-cd47b957ad4e/82831533157.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d5fe76d2-0184-478b-8828-9acc1522e9be/wudowomiwufekeforupi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/46e0e526-7742-42f7-9730-609de583b7fb/nusudoturiba.pdfIn PDF document text
- https://6ec3981f-6443-463b-a164-91fc69f101d9.filesusr.com/ugd/7603ae_e078b71a846c475a9df6df29931e71c8.pdf?index=trueIn PDF document text
- https://6c036dbd-b327-4678-b778-de8a2ee7bb50.filesusr.com/ugd/ed64d2_d7ac3b02ce41483eab13fa4873b954af.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/c21026bd-7057-4681-a986-03146724cc26/is_distance_bracelets_legit.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b95b3a24-0774-498d-8b4c-cee06d5b6e8b/list_of_synonyms_and_antonyms_for_6th_grade.pdfIn PDF document text
- https://s3.amazonaws.com/tarajix/power_book_2_cast_cane.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d2da.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD2DA | 5176 bytes |
SHA-256: 22be2f3863b871c9bebbf9a689e05838f644dd2d194e57a1cf247f8eb80631f9 |
|||
font_01_sfnt_off0000e45b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE45B | 11128 bytes |
SHA-256: c749f53e57e22edb8b4ca1390de78e2a46cadda8c01e4f1991b5eeba742f6448 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.