MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains numerous external links, a technique often used for phishing or distributing malware. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of links, suggesting an attempt to create a link farm or redirect users to malicious sites. The presence of an embedded URL and the ClamAV detection further support its malicious nature. The document body, though partially corrupted, suggests a lure related to a movie, likely to entice clicks.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/strik?utm_term=pelicula+completa+en+espa%25C3%25B1ol+de+annabelle+3
- https://ziwolowuwuxux.weebly.com/uploads/1/3/5/3/135321756/rojoxizizizobow-fuwixolalufel.pdf
- https://cdn-cms.f-static.net/uploads/4414339/normal_6014dd99b0e5e.pdf
- https://cdn-cms.f-static.net/uploads/4449004/normal_60293c1dee4e9.pdf
- https://cdn-cms.f-static.net/uploads/4365586/normal_603fcbc1e9905.pdf
- https://tofesozexeraj.weebly.com/uploads/1/3/4/6/134610570/8657388.pdf
- https://static.s123-cdn-static.com/uploads/4393752/normal_5fc5c2d67f5f5.pdf
- https://cdn-cms.f-static.net/uploads/4420597/normal_605fbfc2f0e72.pdf
- https://xusuzipurojovup.weebly.com/uploads/1/3/4/3/134325257/0576b850.pdf
- https://pesefusuf.weebly.com/uploads/1/3/4/4/134486856/1063890.pdf
- https://cdn-cms.f-static.net/uploads/4366050/normal_60685144d5758.pdf
- https://saxexowiki.weebly.com/uploads/1/3/0/9/130969873/714979.pdf
- https://dudakodut.weebly.com/uploads/1/3/4/4/134497067/paporopukusi-dafofewago.pdf
- https://sevozinevuzejok.weebly.com/uploads/1/3/4/9/134903388/62f66.pdf
- https://jitegolugitu.weebly.com/uploads/1/3/4/6/134643776/tepetobefaju.pdf
- https://static.s123-cdn-static.com/uploads/4380867/normal_5fe4aad22104b.pdf
- https://cdn-cms.f-static.net/uploads/4415962/normal_606e105d8c97f.pdf
- https://wumefabifu.weebly.com/uploads/1/3/4/8/134888429/9332058.pdf
- https://cdn-cms.f-static.net/uploads/4390056/normal_60128e6c75501.pdf
- https://static.s123-cdn-static.com/uploads/4464715/normal_5fca0c021af68.pdf
- https://static.s123-cdn-static.com/uploads/4370778/normal_600563c5667c2.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/9cbdacc9-311c-41c8-9b29-5c0302b99f36/how_much_oil_in_ariens_compact_24.pdf
- https://uploads.strikinglycdn.com/files/62923153-005a-46c8-bf2f-82d9dc30ce05/jikebiz.pdf
- https://uploads.strikinglycdn.com/files/8befb337-f3a5-4f21-9bdb-5b23a551d886/is_anatomy_and_physiology_harder_than_nursing_school.pdf
- https://uploads.strikinglycdn.com/files/b66ba456-3d4d-4d57-a840-02843f2ea84f/18990095408.pdf
- https://uploads.strikinglycdn.com/files/95a95099-dbee-4111-9e27-cba4fb257644/toro_ultraplus_blower_vac_parts.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00014295.bin83d3cec97a600400017a66d6b7a43754903916171f002dc1337631f702a1033e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14295 | 5640 bytes |
font_01_sfnt_off00015567.bin2533b43e2a48754348e4c5b7e5852f4034fb9cebd3841baf42233ad39061fd6b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15567 | 12448 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.