MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a mass external link farm, with many URLs pointing to other PDF files, indicating a phishing or spamming operation. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and numerous external links are indicative of a phishing lure designed to redirect users to malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xajibur.ru/123?utm_term=news+opening+after+effects+template+free
- http://organize.shop/kannada_challenging_star_darshan_photos89hr9.pdf
- http://kiwirixup.22web.org/dclaration_du_chiffre_d_affaires_auto_entrepreneur_maroc.pdf
- https://newakikijako.weebly.com/uploads/1/3/4/3/134351088/0841eb8.pdf
- https://tonefomemozev.weebly.com/uploads/1/3/4/4/134458928/3022007.pdf
- http://paypallsecurity.com/36431386204oep9y.pdf
- http://venira.su/teeth_occlusal_caries_tonsils_gums_report17789.pdf
- https://dapijapivabug.weebly.com/uploads/1/3/4/3/134338952/wakerupugujigulive.pdf
- http://dream-stat.ru/pumimevigo78e8c.pdf
- https://doxizuzipoleri.weebly.com/uploads/1/3/5/3/135323895/xamifala.pdf
- https://febasenijig.weebly.com/uploads/1/3/1/3/131379808/zawor_lusedufigebid_kexuki_nanoposif.pdf
- https://balimalovi.weebly.com/uploads/1/3/2/7/132710770/pakovawositi.pdf
- https://sobomimaseneke.weebly.com/uploads/1/3/1/3/131379860/b3b78d23be2d8.pdf
- https://lowujowe.weebly.com/uploads/1/3/5/3/135320741/f3037164bd68.pdf
- https://pupiwukonavi.weebly.com/uploads/1/3/2/6/132682553/6254132.pdf
- https://dixozetazexode.weebly.com/uploads/1/3/4/4/134472526/c0fa6690c.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://xegiseko.epizy.com/kobeleda.pdf
- https://4b67404f-136a-46a0-9cf3-151f2d38faab.filesusr.com/ugd/241fd5_0bc59df73559440c8ec2253c2b7e2197.pdf?index=true
- https://5663e088-3595-439c-971a-5873693bee35.filesusr.com/ugd/e98895_e64a97c084ed41c1a9fa3fc8cd154ea7.pdf?index=true
- https://a2c67b61-a01d-4053-b7ad-f1487bca8054.filesusr.com/ugd/24853a_c41384472e25420eaf167a0bf83aefc4.pdf?index=true
- https://6f2fb29c-15f2-4b08-b525-3eb91a7f0a41.filesusr.com/ugd/c3548c_b78e5884466a44658dcb02a46b7438c9.pdf?index=true
- https://8f1ef4f7-3f23-41ef-a3d6-4e5873a175a2.filesusr.com/ugd/d318ce_8f9a9bb82bb3475281865a255bcd592d.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010f40.bin3b07646ecb7f527675ae445ed2a22eacec9bc06abce3ef1ce5117014612568cc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10F40 | 5396 bytes |
font_01_sfnt_off000121a7.bin7c0d9f52ed48221c3ff245559850319fc0a77ff5c4ca79bd424ee8aedb219f79 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x121A7 | 11088 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.