MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains a large number of external links, flagged as a 'PDF_SEO_LINK_FARM', suggesting it's designed to drive traffic to other sites or potentially host malicious content. One of the primary external URIs identified is https://xezojetit.ru/strik, which is likely the main malicious destination.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/strik?utm_term=the+redemption+song
- http://mebelrostov.ru/didi_rider_app_australia575wh.pdf
- http://ceiling48.ru/vector_watch_lunan9eqs.pdf
- http://policyhelpcenter.com/when_does_my_puppy_get_better6ryrj.pdf
- http://nemugub.mywebcommunity.org/programa_arquitectonico_de_un_centro_cultural.pdf
- http://jopkapopka.online/ariens_rocket_7_tiller_carburetorft2wn.pdf
- http://lastmarkt.ru/zaxekiwojidifitigiwafaj273.pdf
- http://fruit-ital.space/30215423144q4vmg.pdf
- http://pufivuziviv.mypressonline.com/58114496623.pdf
- http://changepass.online/ukulele_strumming_patterns_4_4d4fg6.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://3f46bf15-0a8c-4e80-b3e5-a2e3bf90e008.filesusr.com/ugd/8e6e76_048c6647d9264a878f96b0783d9c5f70.pdf?index=true
- http://tebaputazaxuva.myartsonline.com/antigona_rozbor.pdf
- https://s3.amazonaws.com/bededuxotulapil/what_do_you_put_in_a_smoothie_besides_fruit.pdf
- https://a161ff94-1a6f-4367-b6f8-8e513a5e676d.filesusr.com/ugd/4c7633_b348ac32ec7e4d0e9b87ed89ca8ddec9.pdf?index=true
- https://ff0b3df2-dc61-4aeb-9024-93fa9b5bc175.filesusr.com/ugd/aa14a9_9bf74ffcbe9044a3ab983d8b40123829.pdf?index=true
- https://s3.amazonaws.com/fakuguvil/76226257077.pdf
- https://s3.amazonaws.com/paxuvagal/44606211269.pdf
- https://s3.amazonaws.com/nuxulikiwab/general_pathology_questions_and_answers.pdf
- http://minivenema.atwebpages.com/84490503877.pdf
- https://s3.amazonaws.com/bisegilupuf/nejonumonoduputavasilo.pdf
- https://s3.amazonaws.com/jiwotarotavuz/47908247758.pdf
- https://s3.amazonaws.com/nuxulikiwab/zodemozasu.pdf
- https://9d349da1-218b-4b59-9e37-2a90cab56d40.filesusr.com/ugd/de9003_378e7f94ec5746f0a45c5a67146c0503.pdf?index=true
- https://s3.amazonaws.com/rodiligarexo/game_archery_world_champion_3d_mod_apk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eb2f.bin94ca58fc3d656dd016fa70d9c9a581daadc89dcc00e5933c05a1fb5661c05b6f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEB2F | 5080 bytes |
font_01_sfnt_off0000fc49.binc977b6a466bf8201e9feed6415b7c1834b96239f8279bd843162a3ccf44ef29c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFC49 | 11308 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.