MALICIOUS
184
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous embedded URLs designed to appear as a link farm, but a critical heuristic indicates these redirect to known malicious infrastructure. The primary malicious URL identified is 'https://crophysi.ru/strik?utm_term=ramana+maharshi+all+books+pdf'. This suggests a phishing or credential harvesting attempt disguised as a resource document.
Machine Learning
- Nyx PDF Classifier malicious score 0.9947
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://crophysi.ru/strik?utm_term=ramana+maharshi+all+books+pdf In PDF document text
- http://gnfcns.info/what_is_presonus_sphereau0j7.pdfIn PDF document text
- https://bitoranajezope.weebly.com/uploads/1/3/1/4/131453137/8175280.pdfIn PDF document text
- http://buytoday.cc/offline_games_2020_downloadnearh.pdfIn PDF document text
- https://metuliwilive.weebly.com/uploads/1/3/4/3/134386481/7544215.pdfIn PDF document text
- http://vsedlyatebya.xyz/ridunodivl8zdp.pdfIn PDF document text
- http://kufafukedexepix.mygamesonline.org/sanowozapoxoweloduxafe.pdfIn PDF document text
- http://tuvivukaroj.mygamesonline.org/2000_calorie_diet_plan_to_lose_weight.pdfIn PDF document text
- http://torchqbfl.fun/mesezazunegopc2t2b.pdfIn PDF document text
- https://rofixuninapo.weebly.com/uploads/1/3/5/3/135313709/vazavonam.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://fedorahosted.org/lohitIn PDF document text
- https://uploads.strikinglycdn.com/files/bbcd0645-626a-4000-9bec-54b1a660a821/sigakonitijuwejufijaruwox.pdfIn PDF document text
- https://94db4134-5784-44c5-a63d-963e509970fa.filesusr.com/ugd/9c58c5_f4005cc909874783b899b0f66d821695.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/3a77d0f8-ba18-49ee-9529-892a2a953f4a/what_are_the_first_five_books_of_the_law.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e9103de5-063c-4a98-8445-bb8cfd07ed9e/how_to_read_love_line_on_palm.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e0998eae-50bf-462c-9ee2-34c8f0182c4b/how_to_tie_a_knot_in_a_piece_of_string_without_letting_go.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/764274b0-7d89-4dcd-84de-396f983be73e/what_would_make_a_dryer_not_turn_on.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/34d7558b-3d6c-4a82-9b46-d2796ba9b6aa/zevebubipofokapexumomeni.pdfIn PDF document text
- http://sajomapujozokux.onlinewebshop.net/wazabikamag.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0cad2094-bedd-43e9-8507-f2842253a9dc/how_to_reset_transfer_kit_on_hp_cp4525.pdfIn PDF document text
- https://00c0516a-c822-4344-a779-6f74e039753d.filesusr.com/ugd/9e41f0_4ce5d79722e94d4b9f0725a66c312499.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/a6a4de6a-40f2-402d-a0cd-835dcf3a4ce1/pofer.pdfIn PDF document text
- https://30c0d994-bee2-4d79-bc91-d4aaa7251653.filesusr.com/ugd/0962d9_0b6be13eed2444a0b728060585253ab8.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/dd127274-b6ec-46eb-8e29-d81a5b951d66/what_is_the_purpose_of_a_sensory_neuron.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b8fe5626-da99-4d8e-974e-8dd47a3b4a4c/walikipinigogugukixuni.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00020389.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x20389 | 3396 bytes |
SHA-256: dc4d71ce285fdcd5cc190f2ac55ebe161f09300daf516bb9704fb6cb06182250 |
|||
font_01_sfnt_off00020faf.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x20FAF | 5492 bytes |
SHA-256: b287fbadcb1e22ef7ef4954063b1d0b7928dc6381beb7bb1120530c0618c271e |
|||
font_02_sfnt_off0002222b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2222B | 2516 bytes |
SHA-256: 95ca8ab9c3298789fed2331b6f261c975f5dc51fe469c259b75ecf3a712a106b |
|||
font_03_sfnt_off00022cee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x22CEE | 14276 bytes |
SHA-256: d8813982893e5e08b5cb1028122e1b403583dad24a3ba95a5b9263957d3dae80 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.