MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The sample is a PDF file flagged by multiple heuristics and ML classifiers as malicious, specifically identified as a phishing trojan by ClamAV. It contains a large number of embedded URLs, many pointing to disposable domains, suggesting a link farm or phishing lure. The presence of PDF_URI and PDF_SEO_DISPOSABLE_LINK_FARM heuristics indicates an attempt to direct users to external, potentially malicious, websites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://botokaw.ru/wix?keyword=sex+and+hollywood+black+veil+brides+lyrics
- http://foxilajat.sportsontheweb.net/centrioles_structure_and_function.pdf
- http://pojokup.getenjoyment.net/rujojafofebudodaw.pdf
- http://vefijedos.22web.org/nuxexetanufuzupogo.pdf
- http://garobunatuxovi.scienceontheweb.net/46076756974.pdf
- http://citruss.space/husqvarna_chainsaw_manual_460xqbqd.pdf
- http://medicinfo.online/fipodipejeregi7ngqp.pdf
- http://suvuxivenorum.mypressonline.com/35828296539.pdf
- http://xufamorazogubov.sportsontheweb.net/what_is_true_metrix_control_solution_used_for.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/d15fac6c-bcf9-4752-bd6a-b9953c365c72/zavidobofusupidik.pdf
- https://s3.amazonaws.com/fajeloninesitel/serta_adjustable_bed_base_reviews.pdf
- https://uploads.strikinglycdn.com/files/a93cab1b-1549-44ba-9465-3e17ba9814e8/how_to_study_for_ncct_medical_assistant.pdf
- http://telusomabufa.onlinewebshop.net/72529139402.pdf
- https://s3.amazonaws.com/sorogamat/87324608725.pdf
- https://uploads.strikinglycdn.com/files/6a5a7c04-1610-4f3a-918a-13f5ba693d16/keurig_k145_cleaning.pdf
- https://s3.amazonaws.com/lanorolowu/fur_elise_sheet_music_free.pdf
- https://s3.amazonaws.com/wixanarer/graphic_design_courses_syllabus.pdf
- http://puwagof.rf.gd/pofijuvokisimutivale.pdf
- https://uploads.strikinglycdn.com/files/93eb0940-c05e-4cac-be63-a8d02e52de64/craftsman_lt1000_battery_walmart.pdf
- http://derekom.rf.gd/25964210666.pdf
- http://dezinolabebosod.atwebpages.com/latila.pdf
- https://s3.amazonaws.com/wibadinavosunom/clearance_certificate.pdf
- http://xujekapowizi.epizy.com/genetics_practice_1_basic_genetics_answer_key.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dd2f.bin28c2ee57da3dcffd9232d206e58132b63174eeba82d76cd451e09f640c38ab38 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDD2F | 5656 bytes |
font_01_sfnt_off0000f085.bin07e6ee10218630e512034a24903aa330b3a957951e566d5543389c1d0f3fb17f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF085 | 10796 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.