MALICIOUS
244
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of embedded links, many pointing to disposable domains and redirector infrastructure, indicating a link farm or phishing attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were extracted, the PDF structure and embedded URLs are indicative of a malicious document designed to redirect users to potentially harmful sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://yafferge.ru/strik?utm_term=short+summary+of+the+castle+of+otranto In PDF document text
- http://kartaidatodemeleri.com/1011157280lyrux.pdfIn PDF document text
- http://nosinoski.shop/sofewumezagadelipijugs08g.pdfIn PDF document text
- https://cdn.sqhk.co/foroboreb/jcOILid/mojuwisufobosizanovanus.pdfIn PDF document text
- http://gojoboli.iblogger.org/sovadamatokigudaze.pdfIn PDF document text
- http://uk-delfin.ru/diserakafifefasasijolafip80qba.pdfIn PDF document text
- https://cdn.sqhk.co/mosepoxik/dc0iahj/72248389125.pdfIn PDF document text
- https://cdn.sqhk.co/kawonidoza/TidMRgj/22894056748.pdfIn PDF document text
- http://eglo.club/98927847426pubt9.pdfIn PDF document text
- http://kadesevi.iblogger.org/auto_air_conditioner_repair_cost_guide.pdfIn PDF document text
- http://freehookup.xyz/nurixajaruvinupamegogipefpbv3z.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/zakunafu/baponunuvu.pdfIn PDF document text
- https://s3.amazonaws.com/forupokisip/blair_witch_size.pdfIn PDF document text
- https://e21f0dd0-e693-4a2a-aa38-6cab66162128.filesusr.com/ugd/34eed6_ba0fbe0758114bd1acdd572b9c635dd9.pdf?index=trueIn PDF document text
- https://8ac5c8e1-9174-427d-95c2-90bebb9f105a.filesusr.com/ugd/44b221_431c5bd49b9749f6afae0c655bbd3247.pdf?index=trueIn PDF document text
- https://7404da97-7fcf-4d5f-9d5f-3f8644e6773a.filesusr.com/ugd/35f767_18051e29202341609cc9886a5542b7b3.pdf?index=trueIn PDF document text
- https://ad0d0dbb-669b-46a9-85df-79487014a0f3.filesusr.com/ugd/00d95d_0f5267d3d39246df8d7ce27ccc876ff8.pdf?index=trueIn PDF document text
- https://6f46ab72-b8e3-4ec2-8f01-cb5d6491dab7.filesusr.com/ugd/9a120b_d369fadccd4049bd829b9ae0e91fbc7d.pdf?index=trueIn PDF document text
- https://cb47f074-0476-4434-b381-5672a365cab8.filesusr.com/ugd/c46c8a_0d5e6b5751c345449fdec6c3ad52bdf6.pdf?index=trueIn PDF document text
- https://d6ac5066-27fc-4e71-a07d-b30af50dfe8b.filesusr.com/ugd/934fc3_794a994dfdec4a5286069bd4e0375f20.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000109d3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x109D3 | 5324 bytes |
SHA-256: 69002e9f49b01ccff6022641f8f1633c6b6ce97199c13a7bdfc4762aef92c660 |
|||
font_01_sfnt_off00011bcb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11BCB | 11168 bytes |
SHA-256: ee657f06e36e392a30e91ebdf099827391cc28846ca25efb90ce6653bbdeda01 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.