MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The file is identified as malicious by ClamAV and an ML classifier, with heuristics indicating it's a link farm on disposable hosting and contains external URIs. The embedded document body, though heavily obfuscated, appears to reference a 'Greenworks 1800 psi pressure washer warranty', suggesting a lure. The primary IOC is the URL 'https://jacksth.ru/strik?utm_term=greenworks+1800+psi+pressure+washer+warranty', which is likely used to redirect the user to a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/strik?utm_term=greenworks+1800+psi+pressure+washer+warranty
- http://pimamuxup.22web.org/what_is_classroom_management_strategies.pdf
- http://jedugefipevama.iblogger.org/anand_telugu_movie_full.pdf
- http://vejefulolite.22web.org/telugu_wedding_invitation_video_templates.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://babematalal.epizy.com/sejowubow.pdf
- https://af30af13-e0b7-4de0-aca7-7783c01eade2.filesusr.com/ugd/9757e7_3b66e4ade111403c9e22fac462b65801.pdf?index=true
- http://lofomaseforuz.rf.gd/mepotavolofalozuwaloxena.pdf
- http://sanafadutu.rf.gd/gowezafi.pdf
- http://kosirokuki.epizy.com/finding_the_perimeter_of_a_semicircle_worksheet.pdf
- http://zusufiwopimi.rf.gd/city_of_heavenly_fire_graphic_novel.pdf
- https://uploads.strikinglycdn.com/files/428e2a9f-3352-49db-b854-7514d1df79a3/27699327662.pdf
- https://s3.amazonaws.com/tiluwisulepam/iit_kharagpur_mba_application_form_2019.pdf
- https://s3.amazonaws.com/juzowilipi/pocket_ref_4th_edition.pdf
- https://uploads.strikinglycdn.com/files/694f8d93-0203-4fec-9364-646f63ddfb95/94890751851.pdf
- https://uploads.strikinglycdn.com/files/0dae2d59-e321-4178-a7ef-5edd4694210b/welewufipaxiwiduxogadifuz.pdf
- https://uploads.strikinglycdn.com/files/7c637a73-fc61-477c-8c01-83583105c6e6/how_to_get_unstuck_borderlands_2.pdf
- https://3b044092-e341-4c69-a8e2-52b14fc1865f.filesusr.com/ugd/370021_86d030584fcf4366bdcdd81704da70f1.pdf?index=true
- https://uploads.strikinglycdn.com/files/cf86da47-080b-4590-9125-28edee1b8755/64933877747.pdf
- https://s3.amazonaws.com/dutuzanob/neribebab.pdf
- https://8a833fea-7c9a-4d2e-a5a7-d3590f42a3e5.filesusr.com/ugd/9aab09_58005f46866f49ccb16db85bfad37839.pdf?index=true
- http://koluriv.rf.gd/block_diagram_of_8085_microprocessor.pdf
- http://wowulikuvej.rf.gd/bioenergetics_mcqs.pdf
- http://zemadepa.rf.gd/what_essential_oils_help_with_emotions.pdf
- https://19f621d4-ab03-49b5-bf1d-c78de40104d4.filesusr.com/ugd/bc84a3_f9234679a87949058fa8c89989a82e8c.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ea5f.bindf6a7e0b5dfd116b41691e213c77306a97109bd353d90ba1cd93bbca81eaacf2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEA5F | 5552 bytes |
font_01_sfnt_off0000fd60.bin7c7d59b808c42a5d222025510587074adad534f13073449b68c8595aeca94429 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFD60 | 10916 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.