MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9980
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lozipotod.ru/strik?utm_term=the+silva+mind+control+method+in+hindi+pdf+free+download PDF link annotation
- http://xemolitaxixa.22web.org/3d_holographic_projection_technology_seminar_report.pdfIn PDF document text
- https://cdn.sqhk.co/xejudawadoni/Pii7Kgj/sowamaromut.pdfIn PDF document text
- http://suvexuvigijorup.22web.org/abbreviated_injury_scale_2020.pdfIn PDF document text
- https://cdn.sqhk.co/kotafuli/MGhbgcO/frp_bypass_apk_galaxy_s8.pdfIn PDF document text
- https://cdn.sqhk.co/gafisasiwu/jdgKOEF/stick_shadow_war_fight_mod_apk_home.pdfIn PDF document text
- https://cdn.sqhk.co/xeduwukaxusa/Bhjgehc/fakeruz.pdfIn PDF document text
- https://cdn.sqhk.co/resilano/igjeN7k/war_and_order_forum_deutsch.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- http://fidotetunuxezi.epizy.com/what_is_hollow_man_exercise.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/89856921-7d18-4a79-a5bd-5efce1478ea3/lobisawozolasotexomoguz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/379686c4-1175-43e3-8145-902a272aa1ac/how_do_you_light_a_gas_oven_pilot.pdfIn PDF document text
- https://28a90398-13b1-4b58-b54c-ed045a6bddf2.filesusr.com/ugd/7e9e1f_44302a6759874901a159d3009c6a7f9f.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/62c8fbee-5379-4b48-895e-c9f0715bdd15/vifibepesoz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ea0d99da-4352-4302-bf16-963738abcf35/how_to_make_phthalo_blue_green.pdfIn PDF document text
- https://7e8267f5-6380-480e-ad72-df526eaefc07.filesusr.com/ugd/cbe325_ef1e9b4d964448dca809612af04998f0.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/7b5ff8e5-da87-4766-9fd8-5ca70946275d/30690465917.pdfIn PDF document text
- http://nemogijikipa.epizy.com/29250311954.pdfIn PDF document text
- http://bukadalisurofez.epizy.com/fuelseurope_statistical_report_2019.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7786ba1b-f9e4-4e9e-8540-91d5a3c1259a/bolakezajabis.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/910c1042-82a1-4670-93fe-2c0ad034cf4f/cien_anos_de_soledad_pelicula_online.pdfIn PDF document text
- https://77047a80-9f17-4504-a563-a097c25ca12e.filesusr.com/ugd/5c8b2f_e38f8b6ced204558bc240f851a113187.pdf?index=trueIn PDF document text
- https://7f1158f2-e44e-4cac-991a-806210d1dc3e.filesusr.com/ugd/e4a8e1_811e08fcd50248fc9109132b036ebbaf.pdf?index=trueIn PDF document text
- https://de2a8dfc-dc8d-4d62-be3b-f97abdd17bf6.filesusr.com/ugd/c722c2_268c0129ad994e8cad8adf920d076361.pdf?index=trueIn PDF document text
- https://c931c956-7f53-4e4e-96dc-27d7f003ba63.filesusr.com/ugd/b80c10_eae9129d791844b39c800e3679db3051.pdf?index=trueIn PDF document text
- https://5634f520-c25d-421d-ab67-3d94505d13cb.filesusr.com/ugd/1b85ab_d501151a3a9d46ecbc2fdf8a23389347.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/8630ccbc-dbce-4916-afcc-94dfc75668fd/ridapogesarinuwiwavitoz.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f1e3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1E3 | 8792 bytes |
SHA-256: bd485545444bb54ce0334dc38828563b72515935a3f198f3fd09755922aa41ce |
|||
font_01_sfnt_off00010ef3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10EF3 | 5284 bytes |
SHA-256: a5af176c9faf555262ddce71580b3198cab6954f6b9a3ae549a5871b862ae26a |
|||
font_02_sfnt_off000120cc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x120CC | 11408 bytes |
SHA-256: d66494014fb4142091c6e6f083a514a0c9d102d5b293c8e2f065ef68e8766d1c |
|||
font_03_sfnt_off00014739.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14739 | 4324 bytes |
SHA-256: 05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.