MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, flagged as a 'PDF_SEO_LINK_FARM'. One of these links, 'https://jumiwimov.ru/strik?utm_term=be+here+now+ram+dass+paperback', is identified as an external URI and is likely the primary malicious lure. The ML classifier and ClamAV detection strongly indicate malicious intent, consistent with phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/strik?utm_term=be+here+now+ram+dass+paperback
- http://tehnikator.ru/1105739659954ncd.pdf
- https://cdn-cms.f-static.net/uploads/4462368/normal_603d1d5c67cde.pdf
- https://cdn-cms.f-static.net/uploads/4492294/normal_5fe9ae0a0439b.pdf
- http://lnstagram-helping.live/comcast_ref_code_s0a00_after_power_outage4d6s8.pdf
- http://hytri.com/metformin_hcl_1000_side_effectshv8yf.pdf
- http://prizinsta365.online/building_cheats_for_sims_4_pcjdqcy.pdf
- https://cdn-cms.f-static.net/uploads/4448129/normal_6033bd78a978a.pdf
- https://cdn-cms.f-static.net/uploads/4416496/normal_5fd3ce779fd0e.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/kulinisokakewi/custom_bottom_navigation_bar_android_studio.pdf
- https://e082b6be-64c0-45f6-a8ff-82b9c6f476f0.filesusr.com/ugd/1479de_ee5ce2de57b14e278f61ab81cb5f3911.pdf?index=true
- https://s3.amazonaws.com/buxoparadazegu/chamakam_in_kannada.pdf
- https://s3.amazonaws.com/vufupu/wuzebinonilobep.pdf
- https://0298dc5a-7924-4276-8279-06452a5288da.filesusr.com/ugd/b30cf0_c9db1740790243fc801ae1315fac1da2.pdf?index=true
- https://e8ceee85-86bf-4804-80ab-d7a1511cbcf5.filesusr.com/ugd/38650a_83cee60fb04b491d9624e7a40f6798ef.pdf?index=true
- https://s3.amazonaws.com/duzexefemosaxe/36198443781.pdf
- https://s3.amazonaws.com/kezemiradigu/ice_hockey_score_sheet.pdf
- https://4fbc56e1-d9a2-4996-be1d-38f9cd263936.filesusr.com/ugd/b1afee_86c9f69ff47b4140861ff06a7480111b.pdf?index=true
- https://uploads.strikinglycdn.com/files/831f9a66-a745-40a1-99f1-283553d899fe/pejibixinopofejokitisu.pdf
- https://s3.amazonaws.com/juzewojavomofew/tusirebuwenivudazodo.pdf
- https://s3.amazonaws.com/wuvepilamamuse/rapewewitopav.pdf
- https://s3.amazonaws.com/lejivugeleguwod/bleacher_report_ne_pats.pdf
- https://uploads.strikinglycdn.com/files/89717a08-5048-49b4-9115-20a310052e10/buffalo_rice_cooker_troubleshooting.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f8a8.bind95125a4b2f6486bf47711912311a41ce292cbc5ea5f8ba443c50e846a0d772f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF8A8 | 5624 bytes |
font_01_sfnt_off00010ba7.bin06f7219093fe21425da69ae80f3d34245b735cd462847b7f1f6ec85b351222e8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10BA7 | 10836 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.