MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating it contains a large number of external links, many of which are likely part of a link farm. One of the embedded URLs, 'https://traffnew.ru/strik?utm_term=chocolate+chip+pound+cake+with+pudding', is flagged as unknown reputation, suggesting a malicious intent to redirect users. The PDF structure and the presence of embedded links strongly suggest a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffnew.ru/strik?utm_term=chocolate+chip+pound+cake+with+pudding PDF link annotation
- https://kopadababipa.weebly.com/uploads/1/3/4/5/134502609/ridudutobirefas_nonuzovufos.pdfIn PDF document text
- https://xifobosakup.weebly.com/uploads/1/3/2/8/132815359/5295631.pdfIn PDF document text
- https://jurosoke.weebly.com/uploads/1/3/4/5/134529251/ded11e8f7a.pdfIn PDF document text
- https://pebawozo.weebly.com/uploads/1/3/4/8/134865175/zipudevobuzelenoza.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/04980010-88e1-4d23-97c3-b17d577e4e8e/tate_no_yuusha_no_nariagari_raphtalia.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5323db10-50c9-4883-8d0a-d563a0953bc8/sipaxizefureribedita.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/abea03fb-d58c-42fb-aa39-5257f7379fef/23703105251.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fc2fafd0-69dc-4d80-82d9-213209382f9c/48175149911.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc124bf3dfdd95b60d690c4/t/5fd12526e6119b7af216eacd/1607542054791/wood_craft_ideas.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9ec818d0-4a08-4d22-9503-a2d1d5fdee8b/gukisiruwafeguwudux.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/037786d8-af0f-4d41-8629-c3502421cc63/caminando_con_dios_versiculos.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/08222c81-e6e6-4f81-9881-64700588f902/95488608156.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cbab6a4a-6ebd-4844-8f81-84c12cd89fa8/tadonofisukivufemijugon.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/54c17260-517a-4ce2-ac71-5a1684b3e45c/rosawimix.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ca5d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCA5D | 5124 bytes |
SHA-256: 2748dfb0b08688fd10369318401e040315b574b2629daf43343a4f5fe0069742 |
|||
font_01_sfnt_off0000dbdb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDBDB | 11312 bytes |
SHA-256: 7bc64baf0b6427a6c2a4f7cd825fb56119250f6f4ab77f3b6789d07aa06d37fb |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.