MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are generated in a way that suggests a link farm for SEO purposes, with some pointing to potentially malicious domains. The presence of urgency language further supports a phishing or malicious redirection attempt. ClamAV and ML classifiers also flagged this PDF as malicious, indicating a high likelihood of malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/strik?utm_term=how+long+does+fcra+background+check+take
- https://valefeka.weebly.com/uploads/1/3/5/3/135345526/fumowajazivezej-suleweve-matixepi-vitusu.pdf
- https://cdn-cms.f-static.net/uploads/4496165/normal_600bc81e35e46.pdf
- https://cdn-cms.f-static.net/uploads/4410190/normal_5fd1573142920.pdf
- https://robevumike.weebly.com/uploads/1/3/4/7/134767989/samigopigor.pdf
- https://vulajavup.weebly.com/uploads/1/3/4/6/134683256/wawavunewebu_tavafowonilu_zibitir.pdf
- https://fepaxumezo.weebly.com/uploads/1/3/4/3/134320712/9725903.pdf
- https://lonawapusar.weebly.com/uploads/1/3/0/7/130776864/742620.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/e37ccfb9-5855-4a6e-89f7-ddb8edd1c3aa/all_american_921_pressure_canner_for_sale.pdf
- https://uploads.strikinglycdn.com/files/367f820b-2be9-4be2-8b82-f154f3dbd52d/fofudoxozami.pdf
- https://uploads.strikinglycdn.com/files/5f61a1dd-584b-4f4c-be43-7cb4fa134607/garmin_405_watch_strap.pdf
- https://uploads.strikinglycdn.com/files/3c07e22c-0808-47cb-8af8-06096f47fcb9/12847415662.pdf
- https://uploads.strikinglycdn.com/files/06b3107a-b351-41d4-92fa-aebd881965cf/9975984945.pdf
- https://uploads.strikinglycdn.com/files/8abfee4b-b540-4827-b881-8ae0fad52664/lorugepod.pdf
- https://uploads.strikinglycdn.com/files/2a158ac1-7e69-4b50-bc29-bdc83f2dedee/xotewosudezubutiwixafobos.pdf
- https://uploads.strikinglycdn.com/files/9d222b05-f52e-4eaf-bb82-7844173bc2a3/xerox_workcentre_3325_reset_admin_password.pdf
- https://uploads.strikinglycdn.com/files/dc79a9e7-ce69-4f01-bed0-72142d1e2d87/jafimasipobirefiv.pdf
- https://uploads.strikinglycdn.com/files/edc3e67d-6389-4ac7-a886-efd20fb0e9ab/oshenwatch_app_for_iphone.pdf
- https://uploads.strikinglycdn.com/files/0f04a2cb-0d73-4908-b1b0-0fcccd09c161/james_joyce_araby_theme.pdf
- https://uploads.strikinglycdn.com/files/c4dfe9c7-a789-4d2c-a005-7ff34c926fc4/56080283216.pdf
- https://uploads.strikinglycdn.com/files/ca734ebf-af07-49cc-bf8d-5e509a9a3499/22251389691.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001476c.bin916e3b9394b2e99a985941d16d0afd4d3c38ff937282d4c484ad3dbb71f7a040 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1476C | 5540 bytes |
font_01_sfnt_off00015a54.bina813d55a3bcdba6afab57efa1ef93562841efdb5292401ff346b0386a961a315 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15A54 | 11180 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.