MALICIOUS
244
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged as malicious by multiple heuristics, including a critical finding for linking to known malicious redirector infrastructure and a large number of external PDF links, suggesting a link farm or SEO manipulation tactic. The ML classifier also gave a very high score. While no scripts were extracted, the embedded URLs and the nature of the heuristics strongly indicate a phishing or malicious redirection attempt, likely delivered as a spearphishing attachment.
Machine Learning
- Nyx PDF Classifier malicious score 0.9973
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://crophysi.ru/strik?utm_term=miniature+german+shepherd+puppies+images In PDF document text
- https://cdn-cms.f-static.net/uploads/4424007/normal_5fdb2525b4fa6.pdfIn PDF document text
- http://fagumawegoleleb.mypressonline.com/affidavit_of_relationship_sample_letter.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4393208/normal_5fe60c10933d5.pdfIn PDF document text
- https://wufirojotuxo.weebly.com/uploads/1/3/1/3/131398242/2872408.pdfIn PDF document text
- http://tapozifokun.mywebcommunity.org/ronabakegiloxitud.pdfIn PDF document text
- http://vojemodipu.sportsontheweb.net/jikajudufu.pdfIn PDF document text
- https://xafukulirodut.weebly.com/uploads/1/3/1/3/131379356/870fd47c9071.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4382423/normal_602dd5901224e.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4419192/normal_605b85fb24f47.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4384464/normal_600e0693c3b3e.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://5a6df620-610b-4d6f-8f1b-71e936bb70bc.filesusr.com/ugd/1f5cef_3c6f7d789f58466c940a727e4db19980.pdf?index=trueIn PDF document text
- https://4c38db24-2924-4bf2-81c9-04860d987a69.filesusr.com/ugd/a68d8f_784b7981b8a04c61b677856d815795ff.pdf?index=trueIn PDF document text
- https://12c48f50-3553-44c7-a31c-19fc5df83d07.filesusr.com/ugd/7e0eb0_e6a2912b8c7f4209852084ad920b6eb3.pdf?index=trueIn PDF document text
- https://254b3b0b-79dc-4992-827c-fd4bb3db3178.filesusr.com/ugd/f515ca_a0ea05e872fb4374af41ef022b2efb57.pdf?index=trueIn PDF document text
- https://12c48f50-3553-44c7-a31c-19fc5df83d07.filesusr.com/ugd/7e0eb0_a1ea9de2f7254b9090dac8de6aad45d9.pdf?index=trueIn PDF document text
- https://1eba3b37-3dce-45e8-aa15-e51a58efc0fe.filesusr.com/ugd/89e37c_efd19bf54ca745a7b0fb28ccb4b7b748.pdf?index=trueIn PDF document text
- https://eb7ae0bc-69c2-4833-8adb-ed465737bb77.filesusr.com/ugd/23493e_88a2fd6fe073413fa5d41f5e42baeb54.pdf?index=trueIn PDF document text
- https://f72e0e13-a873-49c5-9cb5-3c2848b8c5b2.filesusr.com/ugd/f8ba4b_912d11e9a5c5452593b4455876c36b62.pdf?index=trueIn PDF document text
- https://d451e762-8e00-4155-9971-9512d28d2528.filesusr.com/ugd/b52961_ecdb39253a87458892bde54f291567a8.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/2887af20-42d6-450d-b971-5b0baa398046/kezuwesomuxolabulona.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/44621f5d-d103-47fc-838c-84a41bde7742/why_cant_cells_store_large_quantities_of_atp.pdfIn PDF document text
- https://6e3eaeb2-b9dd-4462-8b56-96c59beebd9a.filesusr.com/ugd/dcc11b_32cc50f351e7496a8ae0e176db6e938a.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/145c2a79-13dc-4f5a-94b6-fe07f52b4ada/the_art_of_power_thich_nhat_hanh_quotes.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f5de.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF5DE | 5348 bytes |
SHA-256: 1e8c0111e59add2bf679d4eae2e3eb13841f1de0322d33a7119eb769edb5b0bd |
|||
font_01_sfnt_off000107e8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x107E8 | 8156 bytes |
SHA-256: 809475ed0ff5ffdf3b873a968a64602aaa24e0c116d1aa2c473c9628891732df |
|||
font_02_sfnt_off0001229c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1229C | 10936 bytes |
SHA-256: 87989691b1560d904ed344ef5dc105a31f132fcacc7480a70e3c04a54b633bbd |
|||
font_03_sfnt_off00014843.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14843 | 16512 bytes |
SHA-256: 20cde93dd26cc844a52735c985ca13aa4b3b3897aa87c998df43ca580712f53d |
|||
font_04_sfnt_off00015e45.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15E45 | 1736 bytes |
SHA-256: 1648accd5638f26481c437d0e436fdfb03edab78dab75f4e73239278c8cddc19 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.