MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
T1553.005 Mark-of-the-Web Bypass
The PDF contains numerous external links, many of which are SEO-optimized and point to other PDF documents, suggesting a link farm or redirection mechanism. The presence of a 'MFA Lure' heuristic and a suspicious URL related to 'google authenticator download apk' strongly indicates a phishing attempt aimed at harvesting credentials or session tokens. ClamAV also detected this file as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
MFA / one-time-code harvesting lure high SE_MFA_LUREDocument asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://garglob.ru/pbw?utm_term=google+authenticator+download+apk
- https://cdn-cms.f-static.net/uploads/4466411/normal_604509dd4ccf8.pdf
- https://pigabatanez.weebly.com/uploads/1/3/1/3/131380253/vuzurofikapaxume.pdf
- https://vesedosaripiwuj.weebly.com/uploads/1/3/1/6/131636692/8699847.pdf
- https://jowidirususonin.weebly.com/uploads/1/3/0/7/130775515/ee9c935c522.pdf
- https://cdn-cms.f-static.net/uploads/4407781/normal_600b39a3add2f.pdf
- https://sazigusejif.weebly.com/uploads/1/3/4/7/134771803/nupavazuwarovoraga.pdf
- https://cdn-cms.f-static.net/uploads/4490739/normal_604f032072133.pdf
- https://cdn-cms.f-static.net/uploads/4409394/normal_60413aa5802df.pdf
- https://cdn-cms.f-static.net/uploads/4410016/normal_6054dc1d7c430.pdf
- https://puzemebakojufem.weebly.com/uploads/1/3/4/2/134234574/pikawogeridij.pdf
- https://cdn-cms.f-static.net/uploads/4409107/normal_60504a7f8e393.pdf
- https://cdn-cms.f-static.net/uploads/4470017/normal_6052d04d1f126.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/8963056e-725f-4c06-b3ac-f2472f7e7ee9/analog_ic_design_interview_questions_and_answers.pdf
- https://uploads.strikinglycdn.com/files/79959bc2-2d72-4cee-b97d-4d51865f6c41/vumutel.pdf
- https://uploads.strikinglycdn.com/files/b3e9cdde-b9b1-4b58-9b7e-77cb04c6a947/8657994820.pdf
- https://uploads.strikinglycdn.com/files/656ce991-5528-4044-9b4a-3664a84bb7fd/can_i_travel_internationally_without_a_drivers_license.pdf
- http://gozuwef.pbworks.com/w/file/fetch/144497616/risk_assessment_matrix_example.pdf
- https://uploads.strikinglycdn.com/files/3112e5ad-0f4b-4713-af9d-00b00c86b80d/questes_de_interpretao_de_texto_em_ingls_9_ano.pdf
- http://finebov.pbworks.com/f/ergo_proxy_manga.pdf
- https://uploads.strikinglycdn.com/files/7295026c-d011-4c8e-99d7-fcaa1e464103/comparing_and_contrasting_arteries_and_veins_veins_have.pdf
- https://uploads.strikinglycdn.com/files/5f3c45a7-8800-4554-9c5d-5963297268cf/gifted_and_talented_test_questions_for_2nd_grade.pdf
- http://kafunujazuwo.pbworks.com/f/12343895559.pdf
- http://kesowununak.pbworks.com/w/file/fetch/144594783/best_professional_acrylic_nail_kit_for_beginners_amazon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000faaf.bine16c8bf48ecc595a9a19191eb138268c91bb6b8c9cd48a6a128fe358f7f668bc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFAAF | 5344 bytes |
font_01_sfnt_off00010cec.bindb6d49a368ff20d787f52303a0c1e7c5d3b6fd78a2186786bcab7e2b7e0a23aa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10CEC | 11812 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.