MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic. One of the primary external URLs, 'https://dugedepap.ru/strik?utm_term=is+it+better+to+run+longer+at+a+slower+pace', is flagged as suspicious. The ClamAV detection and ML classifier also indicate maliciousness, suggesting the PDF is used to direct users to potentially harmful content or for SEO manipulation.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://dugedepap.ru/strik?utm_term=is+it+better+to+run+longer+at+a+slower+pace
- https://cdn-cms.f-static.net/uploads/4488822/normal_60558ca859193.pdf
- https://static.s123-cdn-static.com/uploads/4389074/normal_5ffe59cf4dd1d.pdf
- http://brightshopbg.xyz/razisapunjqemp.pdf
- http://buyfastedcircle.xyz/brostrend_ac3_linux_drivervg9mi.pdf
- http://power-guard.shop/best_mythological_fiction_books_india58wj7.pdf
- https://cdn-cms.f-static.net/uploads/4444386/normal_602e9cac2c213.pdf
- http://catsism.com/used_saltwater_fishing_reels_for_salebskws.pdf
- https://static.s123-cdn-static.com/uploads/4455670/normal_5feb4049c92b4.pdf
- https://cdn-cms.f-static.net/uploads/4446275/normal_5fd1b868ac56c.pdf
- https://cdn-cms.f-static.net/uploads/4372987/normal_604d3e47aac23.pdf
- http://proita.fun/66757710782u3ca6.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/a8f76a02-19cb-4cd6-b23b-8eec75708610/what_is_hue_saturation_and_luminance_in_lightroom.pdf
- https://f18b8dc1-3ce9-44bd-8712-01435d039869.filesusr.com/ugd/b97cba_c285a575fec645d39c03c5a8bc047d80.pdf?index=true
- https://uploads.strikinglycdn.com/files/d7083fdb-91a7-40df-93f8-2ab00e230900/punorugov.pdf
- https://d6d3a1c5-32ce-46e9-ae92-c5b8d84d65d9.filesusr.com/ugd/a3b54b_4e9aaa6b929e415bb1429a81c8cc0d88.pdf?index=true
- https://uploads.strikinglycdn.com/files/93483e33-3004-4e01-a736-fc5e84cb1c69/tutorial_blender_2.82_espaol.pdf
- https://uploads.strikinglycdn.com/files/44fb72ea-34cd-4816-9234-44528da77356/how_to_unblock_fisher_paykel_dish_drawer.pdf
- https://uploads.strikinglycdn.com/files/e314cdb7-96d9-4526-95c2-151d473117a8/fender_super-champ_x2_120v_guitar_amplifier.pdf
- https://uploads.strikinglycdn.com/files/4b4dd24e-b59a-4a7c-9409-07751b858e23/14607192783.pdf
- https://uploads.strikinglycdn.com/files/6b7c9c02-69a2-4414-a48d-d030147728ea/riello_40_f5_oil_burner_troubleshooting.pdf
- https://uploads.strikinglycdn.com/files/70cd5ac7-574f-4a2b-b98b-37d00d25b1de/yashica_mat_124g_night_photography.pdf
- https://uploads.strikinglycdn.com/files/f53a4704-7e96-49cf-ad3a-fda1077cf8f6/wuteveworakafobibaguwopu.pdf
- https://6f672a44-e16c-4921-a0f1-e3781c0647c5.filesusr.com/ugd/bda22a_a6983927860a4bb7bc9b7c0ae83fdccd.pdf?index=true
- https://uploads.strikinglycdn.com/files/8fd6722a-9cda-4a65-9136-98d9e9d4f4d4/tcp_ip_protocol_stack_basics.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010092.bin847836c8b1d2708f0a97bf5a51621cffcd528ef9a5492d6c9a157c4350063ab9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10092 | 5268 bytes |
font_01_sfnt_off00011297.bin51ebeec29509b87aa858d500e37ac8853184703d07d1f913ce36d8e1dc7764c0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11297 | 1800 bytes |
font_02_sfnt_off00011b25.bin9d0881f128b2bd9b08b632192e6180c7bf1233c453f588bf00c97fc8c062059f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11B25 | 11328 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.