MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffine.ru/strik?utm_term=how+did+buddhism+spread+during+the+tang+dynasty PDF link annotation
- https://sitixibabu.weebly.com/uploads/1/3/4/7/134749551/6382665.pdfIn PDF document text
- https://tibiwurab.weebly.com/uploads/1/3/2/6/132695994/5341355.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://static1.squarespace.com/static/5fc10b71bdb33045eec31c8e/t/5fc18c659ee0f32b878d98a3/1606519912565/vikilajanufejinozujawul.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc0bb2c88c99b6d37a6398e/t/5fc155e73570fb44d1348124/1606505961303/10990943993.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/47894e31-a4dc-4258-913c-29c821148082/22320044967.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc546b6a13a450bab114660/t/5fc7e5a866d87000d3c393e9/1606935977117/54602737987.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc51bc33dfdd95b60f05278/t/5fc934f240f01d111c1f378e/1607021810969/18391581843.pdfIn PDF document text
- https://s3.amazonaws.com/vaxebisapesi/basupibunisino.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc28c84be9b6939511547ef/t/5fc4ecc9a97599144e9359e8/1606741196723/santa_claus_agency_uk.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc4daea8787e879898531d2/t/5fc5c80ebc819f1cf4a12b86/1606797326433/68621325245.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc575ad2bbd740658254770/t/5fc7f022df14a83315450be2/1606938658548/97312624862.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://afe.easia.columbia.eduIn PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00012baa.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12BAA | 5636 bytes |
SHA-256: b0b8e280b6655bea5130975510744e8b235d5528ab4e221cd95d08af05d854f4 |
|||
font_01_sfnt_off00013eb3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13EB3 | 11468 bytes |
SHA-256: e34ecfb6e4525c5768401e7471b744e5f91631e8f9047f09e30067fd26509025 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.