MALICIOUS
182
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.001 User Execution: Malicious Link
This PDF file contains multiple embedded links, with one identified as a known malicious redirector. The document body, though heavily corrupted, appears to contain text related to software and file names, suggesting a lure to download or interact with malicious content. The presence of a link farm heuristic further indicates an attempt to distribute or redirect to malicious sites.
Machine Learning
- Nyx PDF Classifier suspicious score 0.4403
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/aws?utm_term=foxit+reader+free+latest+version In PDF document text
- https://dusexitope.weebly.com/uploads/1/3/4/6/134646398/960b96b0e.pdfIn PDF document text
- https://static1.squarespace.com/static/5fbffea5239b0722912c2f3a/t/5fc0d9eb5147b1480453746a/1606474219750/natadekirejovuv.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc07d836b97992eb55a0df7/t/5fc24506e18c5c478e46379f/1606567175372/trump_wheely_unblocked_games_66.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc0eaf5c89e1c4b8fbe7403/t/5fc857328eecd53e39e78943/1606965043509/cube_city_wars_unblocked.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dd46b6a8-4496-451f-826a-ba6e2f0f8300/oblivion_construction_set_extender.pdfIn PDF document text
- https://static1.squarespace.com/static/5fce83b06ea0cf7c4ed1ee97/t/5fd01825ef76c20f2d3bd235/1607473191395/chronic_indigestion_and_ibs.pdfIn PDF document text
- https://s3.amazonaws.com/fojaxexino/97041135607.pdfIn PDF document text
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe515aa97599144ec559be/1606308187112/pheromones_peptide_hormones_and_steroid_hormones.pdfIn PDF document text
- https://s3.amazonaws.com/jifedefujodu/37275995381.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.