MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a significant number of external links, identified as a PDF SEO link farm. One of the primary links, 'https://pelibifir.ru/strik?utm_term=a+killer+among+us+filming+location', is flagged as malicious. ClamAV also detected this file as 'Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0', indicating a phishing or trojan payload. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/strik?utm_term=a+killer+among+us+filming+location
- https://cdn-cms.f-static.net/uploads/4445869/normal_6054dbcea5f9e.pdf
- https://static.s123-cdn-static.com/uploads/4466135/normal_5feec3f34ed49.pdf
- https://cdn-cms.f-static.net/uploads/4491168/normal_6056d354c040d.pdf
- https://cdn-cms.f-static.net/uploads/4416661/normal_5fe7965a8213a.pdf
- https://tolopexe.weebly.com/uploads/1/3/1/0/131070113/ebe79182ee8b6.pdf
- https://cdn-cms.f-static.net/uploads/4375080/normal_5fd918941f9cc.pdf
- https://pakokapixufepu.weebly.com/uploads/1/3/4/6/134659136/3753844.pdf
- https://static.s123-cdn-static.com/uploads/4417403/normal_6006486174057.pdf
- https://cdn-cms.f-static.net/uploads/4378383/normal_604e98f164ecb.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/nonipesikiri/a_fathers_story_lionel_dahmer.pdf
- https://s3.amazonaws.com/numegubowalonan/dakonugizalava.pdf
- https://uploads.strikinglycdn.com/files/0f9443fa-f3a5-4a64-9d21-eeaf606d2e68/samsung_xpress_m2825dw_imaging_unit_replacement.pdf
- https://s3.amazonaws.com/lebejos/lapipijoduxowobek.pdf
- https://s3.amazonaws.com/pibajuwi/what_supermarkets_sell_gluten_free_products.pdf
- https://s3.amazonaws.com/dowesitobuga/4th_grade_multiplication_coloring_worksheets.pdf
- https://s3.amazonaws.com/pisik/verifone_vx520_manual_change_time.pdf
- https://s3.amazonaws.com/nagev/neziguzumej.pdf
- https://uploads.strikinglycdn.com/files/1ac0dfd9-e2c2-4c38-b24d-8a730ee95dee/rifiwe.pdf
- https://s3.amazonaws.com/dejolavubukugeb/40094148484.pdf
- https://uploads.strikinglycdn.com/files/57486db6-3349-4715-93b2-1bfc2b2c05bd/best_split_screen_survival_games_ps4.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ed4d.bin347bf9352eff5ba70370ca228d9d3b33827eedbcffda3ca7082f028aad44bc74 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED4D | 5252 bytes |
font_01_sfnt_off0000ff1e.bin942909ae7971fa1957c45f8beef1df5d56e3e508d5d2596a977901e21f0c4e77 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFF1E | 10560 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.