MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The heuristics indicate the presence of numerous external links, some of which are hidden or designed to appear as part of a link farm, suggesting a phishing or SEO poisoning attack. The document body, though heavily obfuscated, contains references to 'manual pdf' and application names, likely serving as a lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image-heavy PDF with invisible link to suspicious domain high PDF_SUSPICIOUS_LINK_LUREPDF is a small image-heavy lure with invisible link annotations that send the user to a suspicious high-risk-domain URI. This matches credential-phishing carriers where the visible document is only a prompt and the real collection flow happens on the linked website.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/wix?keyword=adobe+premiere+elements+manual+pdf
- http://grinallex.shop/85245357015nvudl.pdf
- https://kukaweferoba.weebly.com/uploads/1/3/4/7/134754127/sevadeziwizebav.pdf
- https://pupaxuge.weebly.com/uploads/1/3/4/0/134096873/f0780b.pdf
- https://tevaxuxelajuri.weebly.com/uploads/1/3/2/7/132712575/novazim_suxirixitob_mexuxisixekuga.pdf
- https://folenepawesig.weebly.com/uploads/1/3/2/6/132680852/6086167.pdf
- https://wubabenababi.weebly.com/uploads/1/3/4/4/134432193/puforigufijekod.pdf
- http://strita.space/gta_sa_cheats_keyboard_apkwooib.pdf
- https://kibipevanisimak.weebly.com/uploads/1/3/4/7/134770361/5820289.pdf
- https://sawuwirepugasup.weebly.com/uploads/1/3/0/9/130969548/wafoxusud.pdf
- https://soravetojovon.weebly.com/uploads/1/3/4/8/134890923/saxizifeb.pdf
- https://mevidumufodu.weebly.com/uploads/1/3/2/3/132303219/b6711b809c2a1b.pdf
- https://tojumofudino.weebly.com/uploads/1/3/2/6/132681199/bevuwuvi.pdf
- https://kagiwegelugamed.weebly.com/uploads/1/3/1/4/131453087/b4acef0fc9e07.pdf
- http://podcard2020.site/718782916666jdxb.pdf
- http://ig-supportcenter.xyz/wwe_undefeated_game_trailertqwce.pdf
- https://metekazup.weebly.com/uploads/1/3/2/8/132815755/8740714.pdf
- https://fafafupoxojamu.weebly.com/uploads/1/3/5/3/135350358/lutajetus_xajinab.pdf
- https://komuwewolidixat.weebly.com/uploads/1/3/4/8/134871085/gomavikurad_vikomaditun_xejiwakigi_naxelotu.pdf
- https://pepesavujol.weebly.com/uploads/1/3/1/0/131071240/1e90ebe71e5592d.pdf
- https://xikemusuvef.weebly.com/uploads/1/3/4/3/134322181/7588600.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/da4501b4-1d39-4291-9a73-e74cff680cb1/loromilisolevodawoda.pdf
- https://uploads.strikinglycdn.com/files/5a815d0b-f39d-483f-852f-8cb723aa9263/cheap_dirt_bike_for_sale_near_me.pdf
- https://uploads.strikinglycdn.com/files/e2639413-a17f-40aa-a09c-33b0f71d9b57/boy_scouts_of_america_abuse_lawsuit.pdf
- https://uploads.strikinglycdn.com/files/98800989-9b7b-426e-8dea-8ac9fbd53a7b/personal_and_professional_development_plan_sample.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00012493.bin592f9e6fe1e296f49b23546c7ffc87a4cc8bd20bfe52861a2c2b543e0274d6d1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12493 | 5316 bytes |
font_01_sfnt_off00013688.bin0bd92786bb2b18a8ea8728da0aa8385c637519a61933da6262e84c1cc72e0d94 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13688 | 11528 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.