MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan' and an ML classifier indicating maliciousness. It contains numerous external links, suggesting a link farm or redirection to malicious sites. The document body, though heavily obfuscated, appears to be related to academic content, likely a lure to disguise the malicious intent of directing users to external URLs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9989
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/wix?keyword=assigning+oxidation+numbers+worksheet+with+answers
- https://jejenami.weebly.com/uploads/1/3/4/6/134684972/cbcee6d792.pdf
- http://tiktokcopyrighthelpteam.com/how_to_find_the_maximum_volume_of_a_cylinder_inscribed_in_a_spheredo4hg.pdf
- http://amsidisi.xyz/wepujanojiwamuza3al4r.pdf
- https://lepovomika.weebly.com/uploads/1/3/4/7/134701686/9645588.pdf
- http://xepuxesadara.mypressonline.com/apocalypse_meltdown.pdf
- http://how2clever.com/54907956000ylull.pdf
- https://wazexusevawixi.weebly.com/uploads/1/3/0/7/130776334/mozivivuzegamufonu.pdf
- https://turulogir.weebly.com/uploads/1/3/4/6/134641543/7397a8ded80.pdf
- https://kazanuwe.weebly.com/uploads/1/3/2/6/132683097/bivebapuba.pdf
- https://nujetamewude.weebly.com/uploads/1/3/4/8/134881912/firemow-dixapeti-bukevupu-dodalu.pdf
- http://nosilekexiwot.mywebcommunity.org/vuvimenuwora.pdf
- https://vapasunodisina.weebly.com/uploads/1/3/0/8/130873802/xifodoju_poguxofepuj_volazajimifibut_moxakitopis.pdf
- https://levevuwakute.weebly.com/uploads/1/3/4/9/134904524/gudetis_jatevejejide_towolazoraz_togokadimev.pdf
- http://proita.fun/play_youtube_on_android_auto_20209ep0p.pdf
- https://vejegiraforid.weebly.com/uploads/1/3/4/3/134311029/pavovo.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.opentle.org
- https://uploads.strikinglycdn.com/files/6c5e3fe7-c5c9-4851-9d1c-96833793902a/22063080027.pdf
- https://s3.amazonaws.com/likadojivivofu/47929220426.pdf
- https://s3.amazonaws.com/regovadeje/lokuzifofebivib.pdf
- http://nufiwimuzobo.onlinewebshop.net/what_does_linear_plot_line_mean.pdf
- https://s3.amazonaws.com/bajuse/35536502964.pdf
- https://uploads.strikinglycdn.com/files/652e8f30-b1a7-41cb-aaaf-bdded7406aef/kirikusifidakivifazo.pdf
- https://s3.amazonaws.com/julexekubaj/job_handover_sheet.pdf
- https://s3.amazonaws.com/rezugekolaba/98333188832.pdf
- https://uploads.strikinglycdn.com/files/a89bbf8a-64e4-4c1c-93e1-2acd18019113/jazaro.pdf
- https://uploads.strikinglycdn.com/files/1bae5f91-d963-438c-b49b-e440352804f0/a_different_mirror_a_history_of_multicultural_america_chapter_3_summary.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://www.gnu.org/licenses/gpl.html
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001041e.bin9385cade9ed11d155094c5365ab41a887351404ffbf7f7be8dabbb8028df5a85 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1041E | 5560 bytes |
font_01_sfnt_off000116e2.bin0b38f6fd5e0b54bfa22d5adee1cfe00629fe134100fc7cfc1ad14a2ab7974207 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x116E2 | 6148 bytes |
font_02_sfnt_off000126c2.bin95d8fa1b45fd9fbf422308dd1a3a0d3079669956309c845b85d6d606340e0448 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x126C2 | 10964 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.