MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or phishing attempt. The ML classifier and ClamAV detection strongly indicate malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external URLs point towards a malicious document designed to redirect users to potentially harmful sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://golowaki.ru/123?utm_term=appcompat_v7++android+studio
- https://cdn-cms.f-static.net/uploads/4481285/normal_603a91d00db4b.pdf
- http://kovamuwaropepu.getenjoyment.net/punebagoketonamifimi.pdf
- http://lopixerirerenex.mywebcommunity.org/distant_hybridization.pdf
- http://zosuwalerikare.getenjoyment.net/rivunemetixamexu.pdf
- http://suwefazimim.medianewsonline.com/diary_of_a_wimpy_kid_dog_days_movie_free_online.pdf
- https://static.s123-cdn-static.com/uploads/4460682/normal_5fcb5674d07a5.pdf
- http://wijutomotagam.mypressonline.com/gujarat_samachar_news_paper_today_bhavnagar_download.pdf
- https://static.s123-cdn-static.com/uploads/4426066/normal_5feafdec7feb9.pdf
- http://vikiduxa.mywebcommunity.org/kung_fu_panda_2_movie_download_in_hindi_filmywap.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://pujumek.myartsonline.com/54759319691.pdf
- https://29fa80ab-3b21-46a5-a5c9-66d7a3d84e9c.filesusr.com/ugd/eb9fb8_e7d1471c661e49ae93b86f9d97540725.pdf?index=true
- https://0296ecfc-28ae-4fa5-925c-67a25994cace.filesusr.com/ugd/c88839_d161849259ee4b97b581625d3deb469c.pdf?index=true
- https://d80868e2-5d34-4dda-9345-0396294a35aa.filesusr.com/ugd/f9fac6_7fe0b5c12299421d80d492ff1b456b1c.pdf?index=true
- https://1ce8651a-bfbb-4b9a-b1bf-24b3b574775a.filesusr.com/ugd/ac72e0_a26bfab88262444088cd7be8f588c937.pdf?index=true
- http://vubuzixefixa.onlinewebshop.net/balancing_nuclear_equations_worksheet_with_answers.pdf
- https://101c3d73-5e22-4da1-a203-a3a2a794ce88.filesusr.com/ugd/69a512_25c8cc764f51428e8977ec3422cd1ce3.pdf?index=true
- https://e5baaea7-7007-41de-9367-4ebf3ed55875.filesusr.com/ugd/8e1900_cb9e302625e9471cb0d37b50d557dccc.pdf?index=true
- https://46d16763-6c5f-4e19-aa2c-3f4071fcbec2.filesusr.com/ugd/26f730_5299781b3b4b4ed2b197d332f9cfea18.pdf?index=true
- https://336ddc11-c37d-4cd6-9685-7accad2975f7.filesusr.com/ugd/479fa9_a27838f005554a81929ade054c8573ae.pdf?index=true
- https://4a39c6c9-989b-4d11-b2d8-cc0becc7f193.filesusr.com/ugd/ef0078_8207c82ff77349a38174291e91e999bc.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000edd1.bin65f11ce43b2a3eeafbf505d31063c9f60da39b68f3f2712c6015d43bfb5a2ea0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEDD1 | 5348 bytes |
font_01_sfnt_off0000ffff.bin74ad2f931137b5bb382ffea84b91691fa4d4f5593ec83ab488a5c7b4022fa4c1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFFFF | 16792 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.