MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, with a critical heuristic indicating a link farm designed for SEO manipulation. One of the primary links points to a URL that appears to be a lure for accounting and finance MCQs, suggesting a phishing or malware distribution attempt. The ClamAV detection and ML classifier further support the malicious nature of the file, likely serving as a dropper for further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/award?keyword=accounting+and+finance+mcqs+pdf
- http://alcexpress1.xyz/95093684859pd9ft.pdf
- http://gutowofobujibos.iblogger.org/66281439595.pdf
- http://kobujiva.iblogger.org/it_program_manager_interview_questions_and_answers.pdf
- https://zeberafuduzugag.weebly.com/uploads/1/3/2/6/132682167/motewumobif.pdf
- http://idealica-italy.site/kung_fu_panda_3_full_movie_in_hindi_download_filmymeet6tpmy.pdf
- https://zogugixuwomu.weebly.com/uploads/1/3/4/2/134234599/6147002.pdf
- https://jaregufadux.weebly.com/uploads/1/3/4/0/134016720/fijumuno-niberik-moxojif-zewofeme.pdf
- http://kvrovk.xyz/scroll_saw_3d_patterns_freekvrao.pdf
- http://bloomwithdeanna.com/blomberg_dishwasher_e16963h.pdf
- https://menekagamop.weebly.com/uploads/1/3/4/0/134097565/b029cc3161.pdf
- http://expressvpn.store/508051805253zvit.pdf
- http://easy-money-cash.space/wadebotakitiviwiwtnkr0.pdf
- https://belatefa.weebly.com/uploads/1/3/0/7/130775380/d80b352859a493.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://e966359d-176b-477a-9ad9-c314bea94227.filesusr.com/ugd/fa6f14_8ade3b463a68483eb42b56568da89732.pdf?index=true
- https://3b87a2b8-2d13-4e6d-acc4-cbba57692a59.filesusr.com/ugd/50988c_97d4ea47876943ef8f9d6849516be263.pdf?index=true
- https://1f49b3f1-4b09-4f89-88df-03804352fc9a.filesusr.com/ugd/a51aec_b5d25afd973c4f03981a47c862ebe020.pdf?index=true
- https://f421159b-d329-41e8-bc42-072bc93e4c50.filesusr.com/ugd/65d6f7_3dbabc34d9ae463b99d5a2cdd9d51e11.pdf?index=true
- http://veboxin.epizy.com/dediwudas.pdf
- https://564fd4a8-0e6d-4f97-813a-a14a70c45316.filesusr.com/ugd/f90d28_f0d0ec9c2d9b4d248972560b805ebf0b.pdf?index=true
- https://f3874c2d-c116-49c2-b7b6-9300dc8fc43e.filesusr.com/ugd/b11f6d_d4cf600766184f7b96003131988c7031.pdf?index=true
- https://2dcb0092-dd22-4cef-90c1-8c398f802bb7.filesusr.com/ugd/ff3115_e7fd67bbe75d41919cc78e35867f189f.pdf?index=true
- https://7afd96e6-4611-46d4-9b98-d111b897c281.filesusr.com/ugd/154221_4f453a0371734a7cac7ebc9a98f09dc4.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f259.bin58cc8c613cfab2bd366a08ade150c5c66722a9da913f02f91aa3ce8ecbdfb866 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF259 | 5460 bytes |
font_01_sfnt_off000104df.binb3151e3b601a0e3e0aab559a555021526da232b78d1eb4e1f571517a79cb721f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x104DF | 11412 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.