Malware Insights
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains a large number of external links, many of which are hosted on services like weebly.com and cdn.sqhk.co, suggesting a link farm or redirection scheme. One of the embedded URLs, 'https://jacksth.ru/123?utm_term=data+entry+job+salary+in+kolkata', is presented in a way that suggests a lure for job seekers, which is a common phishing tactic. No scripts were extracted from this sample, but the extensive use of external links points towards a phishing or malware distribution campaign.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/123?utm_term=data+entry+job+salary+in+kolkata PDF link annotation
- https://laxivaxof.weebly.com/uploads/1/3/0/8/130874385/kawelerukulotokopigi.pdfIn PDF document text
- https://cdn.sqhk.co/wodelaganav/jE51jij/nazurodobugenewofoga.pdfIn PDF document text
- https://cdn.sqhk.co/pininipata/iiigjha/basketball_referee_training_videos.pdfIn PDF document text
- https://cdn.sqhk.co/purovufizu/evogfjj/xizidobemovexetis.pdfIn PDF document text
- https://cdn.sqhk.co/xedaberetaj/8hehjgi/costume_store_near_me_halloween.pdfIn PDF document text
- https://cdn.sqhk.co/mogizufofuj/gdSK2ZL/new_york_tourist_attractions_map.pdfIn PDF document text
- https://cdn.sqhk.co/favejofu/jdxic5e/jefetuwunaborulemiki.pdfIn PDF document text
- https://cdn.sqhk.co/fapolokid/ieNdWjd/mini_racing_adventures_mod_apk_1._5._2.pdfIn PDF document text
- https://cdn.sqhk.co/waxipefimafa/gijnp88/mogejojog.pdfIn PDF document text
- https://cdn.sqhk.co/mogowepuw/7gjiaiI/buvuf.pdfIn PDF document text
- https://cdn.sqhk.co/feledigowud/9vOhgha/table_tennis_3d_mod_apk_download.pdfIn PDF document text
- https://cdn.sqhk.co/seworani/jigegj2/police_car_smash_game.pdfIn PDF document text
- https://cdn.sqhk.co/takejirasomu/ehhLhdB/major_militia_war_mayhem_mod_apk.pdfIn PDF document text
- https://cdn.sqhk.co/kikolibub/8H5m6c6/zombix_online_mod_apk_unlimited_money.pdfIn PDF document text
- https://cdn.sqhk.co/zekafomaze/jdIiegB/monster_craft_2_android_gameplay.pdfIn PDF document text
- https://nigafabap.weebly.com/uploads/1/3/4/3/134377596/3837591.pdfIn PDF document text
- https://furimulu.weebly.com/uploads/1/3/1/4/131411024/finijusinub.pdfIn PDF document text
- https://cdn.sqhk.co/zujubokave/4gd8jdm/nick_soccer_stars_codes.pdfIn PDF document text
- https://noruwapawufibem.weebly.com/uploads/1/3/0/9/130969999/11025.pdfIn PDF document text
- https://cdn.sqhk.co/duxadikoti/gjqghhj/confined_space_pictures_cartoons.pdfIn PDF document text
- https://cdn.sqhk.co/kerosumumato/jcVjiky/26x1._95_mountain_bike_tire_walmart.pdfIn PDF document text
- https://cdn.sqhk.co/netimupoxojo/dI0d6D2/kodiak_tents_utah.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f57e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF57E | 5060 bytes |
SHA-256: e633692fbb974f04110e844599994d9883262c235ee2d43681b469a9368e87d7 |
|||
font_01_sfnt_off000106d6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x106D6 | 10560 bytes |
SHA-256: bd44ec9e03e617ab63b751d32eaf6f0a0f027ca5f9f0af88f3e58325be910c60 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.