MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, identified as a 'PDF_SEO_LINK_FARM' heuristic, pointing to various PDF files hosted on external services. The primary URL, 'https://soxebez.ru/wix?keyword=raleigh+m20+mountain+bike', suggests a keyword-based lure. The ClamAV detection and ML classifier flagging indicate malicious intent, likely related to phishing or malware distribution through these linked documents.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/wix?keyword=raleigh+m20+mountain+bike
- https://dekitinuro.weebly.com/uploads/1/3/4/8/134871397/vubomef.pdf
- https://lolejubabam.weebly.com/uploads/1/3/1/3/131379737/sevejudax-josilalosi.pdf
- http://lapitubemexidi.mywebcommunity.org/tujefijidaka.pdf
- http://jokojujut.medianewsonline.com/agresti_and_finlay_4th_edition.pdf
- http://xelamoxadavas.mywebcommunity.org/rifusokaxivetoxazokewujo.pdf
- https://kakifimetuwojo.weebly.com/uploads/1/3/4/3/134317364/jegul.pdf
- https://tebafazar.weebly.com/uploads/1/3/4/2/134265880/betolufovowakab.pdf
- http://tejovotemikodes.getenjoyment.net/5683186953.pdf
- http://guzexesuge.mypressonline.com/present_simple_vs_present_continuous_elementary_worksheet.pdf
- https://jedijevabepepox.weebly.com/uploads/1/3/0/7/130739982/sinatuxidutov-kiwunifi-webofobefijaga-nuwotijagejap.pdf
- http://kedepoba.sportsontheweb.net/rudram_namakam_telugu_free_download.pdf
- http://niluwipewuxasa.medianewsonline.com/xakugokuk.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- http://kunimaz.rf.gd/bufupopasalederisakitit.pdf
- https://uploads.strikinglycdn.com/files/780440b5-1b44-4b03-99cb-5b1c4df77114/tone_up_legs_exercises.pdf
- https://uploads.strikinglycdn.com/files/75892cb7-1280-40e6-8c5a-8d93669fd7df/brother_sewing_machine_vx-1120_troubleshooting.pdf
- http://dogumimuzelu.epizy.com/bexar_county_public_records_arrest_reports.pdf
- https://uploads.strikinglycdn.com/files/c5ba3991-bd2d-4954-a398-8df556425fc9/proto_reflex_rail_paintball_gun.pdf
- https://uploads.strikinglycdn.com/files/56445695-7ed5-4878-969d-1a3e75adfb0d/craftsman_edger_trencher_parts.pdf
- http://kivajujudupogij.epizy.com/wagolarebajituwugo.pdf
- https://uploads.strikinglycdn.com/files/dfeacd34-8e9b-479b-8af7-7f25da940a67/jonumoxezego.pdf
- https://uploads.strikinglycdn.com/files/6e42a9e6-946c-4073-a41b-4a2835308174/35055513431.pdf
- http://vugapadilubokis.epizy.com/nigerian_newspapers_online_today_sahara_reporters.pdf
- http://seroroxunabolu.onlinewebshop.net/the_world_s_200_hardest_brain_teasers.pdf
- http://lejiletuvasipib.onlinewebshop.net/how_many_movies_are_in_the_insurgent_series.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f42f.bin473447b8a1ab9594aa6770960720b82224b178280155e21f0f17e8b8c9b63074 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF42F | 5192 bytes |
font_01_sfnt_off000105c0.bin9408efd7228b2c46948c25bf0cde3e78925fdf7822e206b2ba48a6325f942900 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x105C0 | 10188 bytes |
font_02_sfnt_off00012896.bince7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12896 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.