MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, a common tactic for SEO poisoning and phishing. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of links, and the 'ML_NYX_PDF_MALICIOUS' and 'CLAMAV_DETECTION' heuristics strongly suggest malicious intent. The embedded URLs point to domains commonly associated with malicious activity, such as 'leonvi.ru' and 'internet-babki.ru'.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=dr.+collins+pcat+self-study+guide+download
- http://internet-babki.ru/how_to_do_a_double_crochet_for_beginnerscagb9.pdf
- http://likedizar.medianewsonline.com/asia_political_map_download.pdf
- http://rowowesofazov.medianewsonline.com/zofuluzigasoku.pdf
- http://hytri.com/26733456975cye87.pdf
- http://xagakojitogiva.getenjoyment.net/66632811980.pdf
- http://tikopariwoxa.mygamesonline.org/napegeterovofemuxasodo.pdf
- http://amsidgi.xyz/nordyne_furnace_troubleshooting_codes0wglt.pdf
- http://bodaweziwov.mypressonline.com/percy_jackson_sea_of_monsters_villains_wiki.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://9005a25f-7293-4a73-bb0f-bc58e8c16807.filesusr.com/ugd/e3834b_19f5f39828344dbaaf2eb59c31af1084.pdf?index=true
- https://uploads.strikinglycdn.com/files/be273f66-3195-48f4-91e9-68be2895ae16/libro_el_juego_del_angel_completo.pdf
- https://uploads.strikinglycdn.com/files/cdc5c458-3145-46f3-92a5-829f24fdafe4/61778117194.pdf
- https://uploads.strikinglycdn.com/files/6756aba1-33b7-4903-8e03-527690f5a4b4/how_to_deal_with_a_child_with_adhd_and_odd.pdf
- http://bigamutalunu.atwebpages.com/rofafisafug.pdf
- https://uploads.strikinglycdn.com/files/cd48beea-0918-4ab6-9277-58db15de4e36/gejafop.pdf
- https://9abff256-b119-4e75-a612-dfc075f5428e.filesusr.com/ugd/c73517_b3066ba2a9af45fc9d3b4d9c98b7e22b.pdf?index=true
- http://legokejapo.atwebpages.com/how_do_i_return_to_sender_australia_post.pdf
- https://e05653fc-386e-4c8b-889d-738aee72c63e.filesusr.com/ugd/62421a_6d17c8c2d24b4248838d0a256e3bf3c0.pdf?index=true
- https://87c8fc71-818b-4167-bf0d-2ac3bc49ffd1.filesusr.com/ugd/f9d4cd_e0741b9442694a1b892a3cf8cdc82370.pdf?index=true
- https://s3.amazonaws.com/satuja/what_does_historia_mean_latin.pdf
- https://s3.amazonaws.com/dowavelaxam/stihl_ms180_parts_manual.pdf
- https://uploads.strikinglycdn.com/files/6b0702aa-25e4-437b-8688-0f93a851a7b3/jurunakoraverimom.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011d59.binc6bac62697a42d54f31afd0f4545a4f104c71d426599d8b8087a255f3c2adb61 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11D59 | 5580 bytes |
font_01_sfnt_off00013098.bin875f86523bd69d770b541c76210de03e721f945154664f093710b3156fc66331 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13098 | 12216 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.