MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, many hosted on disposable domains, indicating a link farm or redirection scheme. The heuristic 'PDF_SEO_LINK_FARM' and 'PDF_SEO_DISPOSABLE_LINK_FARM' strongly suggest this is a malicious attempt to distribute content or redirect users. ClamAV also detected this as 'Pdf.Phishing.Trojan'. The embedded URL 'https://xajibur.ru/wix?keyword=viper+479v+remote+manual' likely serves as the initial lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9957
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xajibur.ru/wix?keyword=viper+479v+remote+manual PDF link annotation
- https://cdn.sqhk.co/woxemumi/vBfjeif/zotejabojozejoduwiri.pdfIn PDF document text
- https://mepagalupotope.weebly.com/uploads/1/3/4/2/134265457/5386094.pdfIn PDF document text
- https://cdn.sqhk.co/fasotaluvose/km24Kig/minecraft_cookie_clicker_mod.pdfIn PDF document text
- https://wajogivetiwi.weebly.com/uploads/1/3/4/3/134322864/lejijoruzemoro.pdfIn PDF document text
- http://libralab.digital/what_are_the_5_factors_that_affect_biodiversityaxcdi.pdfIn PDF document text
- https://tewabigonin.weebly.com/uploads/1/3/4/7/134760563/moridubuzojuf-darexosanimuf.pdfIn PDF document text
- https://xuvevajepew.weebly.com/uploads/1/3/0/7/130739459/viwuv.pdfIn PDF document text
- https://buvewetaki.weebly.com/uploads/1/3/0/7/130775635/nowanuzonafululo.pdfIn PDF document text
- http://repair-planshetov.ru/ludepefutelumijelinewqzunp.pdfIn PDF document text
- https://nevutero.weebly.com/uploads/1/3/4/7/134716167/rutufizon.pdfIn PDF document text
- http://hiziryigit.online/pidebaxefuvaslh6pc.pdfIn PDF document text
- https://xurigaguk.weebly.com/uploads/1/3/4/6/134635426/kevevotogasozigugap.pdfIn PDF document text
- https://zokelafeg.weebly.com/uploads/1/3/4/8/134889419/9125756.pdfIn PDF document text
- http://haifaiv.ru/games_to_play_in_class_when_bored_on_computerh0t57.pdfIn PDF document text
- https://wujewogo.weebly.com/uploads/1/3/4/5/134586314/e1395e.pdfIn PDF document text
- https://bakubirusi.weebly.com/uploads/1/3/4/6/134680497/6138912.pdfIn PDF document text
- http://normal-id.com/fakoxefutokakexafxt.pdfIn PDF document text
- https://cdn.sqhk.co/rogumabutur/hZm1hdM/lejolorevawaduwekobi.pdfIn PDF document text
- http://netewe9.xyz/29239780950oiuey.pdfIn PDF document text
- http://inscarusa.info/541179521705i0hk.pdfIn PDF document text
- https://cdn.sqhk.co/musutalivun/r4nMWja/sesofegukumasivowupit.pdfIn PDF document text
- http://onlinekartiadesi.com/whatsapp_video_calling_free_download_for_pcgmevd.pdfIn PDF document text
- https://cdn.sqhk.co/gogoturowib/aggrUje/gubifolorew.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://cdb53ace-3f3f-41e1-823e-0ecf3add8ba2.filesusr.com/ugd/47e9e0_12c8fb67002c45d7b7419191c432f3b6.pdf?index=trueIn PDF document text
- https://ce55c564-0e79-48ac-bd91-a034cff8554b.filesusr.com/ugd/bd1fc0_07ef66074f89472a9766a55e055fb958.pdf?index=trueIn PDF document text
- https://f421159b-d329-41e8-bc42-072bc93e4c50.filesusr.com/ugd/65d6f7_7ca76f8259344d4b86080af1327ffd98.pdf?index=trueIn PDF document text
- https://0cc2a7d0-6f33-4335-9ec9-554d9418487e.filesusr.com/ugd/cb4a18_9f6397dea6a840de9a44695a2a94cf47.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fa0a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFA0A | 5136 bytes |
SHA-256: 773cc31b1006c1ba324d821d7d4e9a1cd1a97fbcd231e9ae62a517e7ae37c947 |
|||
font_01_sfnt_off00010b85.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10B85 | 11748 bytes |
SHA-256: 666abcb25b41fddcd1722e971e6f7cbf0625e74f8a8921d3099a75503fb2a8d2 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.