MALICIOUS
172
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document contains a mass of external links, many of which are likely part of a link farm designed to improve search engine rankings for malicious content. The ML classifier and ClamAV detection strongly indicate malicious intent, specifically a phishing or trojan delivery mechanism. The document body's content, 'Bank guarantee vs standby lc', combined with the heuristic 'PDF_SEO_LINK_FARM', suggests a lure to direct users to potentially malicious websites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 7
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://resalured.ru/strik?utm_term=bank+guarantee+vs+standby+lc
- http://nunajurum.iblogger.org/35923453136.pdf
- http://texulateniz.iblogger.org/samsung_top_load_washing_machine_buttons_not_working.pdf
- http://xadimilok.iblogger.org/behringer_xenyx_1202fx_list.pdf
- http://juvovagesubo.mywebcommunity.org/debt_collector_job_description.pdf
- http://sosunimepewe.22web.org/buwulerobegugabu.pdf
- http://wawesoja.sportsontheweb.net/yard_machine_riding_lawn_mower_parts_diagram.pdf
- http://puvepum.getenjoyment.net/jorge_luis_borges_sus_principales_obras.pdf
- http://nitafibejuze.mygamesonline.org/58320205053.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://91e55214-10ad-44cf-a10a-60a9392df58b.filesusr.com/ugd/e1c37d_2b035bd2aa884ea3b94336fc898b0b80.pdf?index=true
- http://dafudezukixoz.epizy.com/yaseen_malayalam_free_download.pdf
- https://dc273c12-e125-4738-b2e6-b96bc4bd5eb7.filesusr.com/ugd/c8df25_bc7c9800c0f64374920ee2caf51287cd.pdf?index=true
- https://89f68ddc-9f98-4e60-8afa-3e0ca6603e9e.filesusr.com/ugd/4725f1_4d0ee9babe074c0b9c491abe706854c3.pdf?index=true
- https://0bdb67af-4c57-4a6e-9706-714cc80719f5.filesusr.com/ugd/fc840b_fe4299027158406f9ab505ebd4dfbb25.pdf?index=true
- https://4b67404f-136a-46a0-9cf3-151f2d38faab.filesusr.com/ugd/241fd5_b16607aba0d54db2bff17e19114ae0ad.pdf?index=true
- http://mubadel.epizy.com/rumble_fish_full_movie_online_free.pdf
- http://desorebo.epizy.com/83887409347.pdf
- https://6dd05bf8-a32e-4ce7-8057-9a1894012cff.filesusr.com/ugd/4ce960_c91697f0f60a4a6ab8ca6d26740b5ef7.pdf?index=true
- https://19a39513-20cc-49d1-a75c-e30ce0314142.filesusr.com/ugd/f99735_d6c603e4e2834fe78003cb1905b21705.pdf?index=true
- http://xilixuludomiti.rf.gd/different_types_of_alloys_and_their_composition.pdf
- http://kizufalugomux.atwebpages.com/srimad_bhagavatam_malayalam_free_download.pdf
- http://tekunobujolid.epizy.com/61331610715.pdf
- https://7ffe38df-ef78-47a1-8632-a9c579db478a.filesusr.com/ugd/8ff694_b28e08beb87b4d1d9fc410e85e22d0e3.pdf?index=true
- http://pinezininefos.epizy.com/clover_water_cooler.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eaed.bin3b38f2c6e8d34f93ae070b8fd91212d1715c35318a997e34f79c0e2a9bd5fe1c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEAED | 5520 bytes |
font_01_sfnt_off0000fdd5.binc467ae69c3d019c02e90372705dabed52507224c4f3e0b51e208a199a95681e7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFDD5 | 10172 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.