MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with one heuristic specifically identifying a "PDF link farm". The primary suspicious URL, https://leonvi.ru/wix?keyword=bamboo+fly+rod+identification+guide, is likely used for SEO manipulation or to redirect users to malicious content. ClamAV detection and ML classification strongly indicate malicious intent, classifying it as Pdf.Phishing.Trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9988
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=bamboo+fly+rod+identification+guide
- https://bebiluredop.weebly.com/uploads/1/3/3/9/133987060/3471463.pdf
- https://libizegenumejav.weebly.com/uploads/1/3/0/7/130775388/6547352.pdf
- https://nelejejo.weebly.com/uploads/1/3/4/8/134883178/7c31e1a75.pdf
- https://sokirokesavosa.weebly.com/uploads/1/3/4/9/134901907/penedidig-xapoweve.pdf
- https://mufiguxibetifo.weebly.com/uploads/1/3/1/6/131607440/770b5bbe1.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://62bfe9e3-d01a-456c-9d14-3ac71290fd99.filesusr.com/ugd/cfe640_8d7b454d98a04772862b77a0d3900f77.pdf?index=true
- https://e590c0d9-b694-44fb-9862-47327b30d8b0.filesusr.com/ugd/89363e_82907e6ecfc548eead53371dafb1e188.pdf?index=true
- https://ec451167-49e0-489e-a150-d7dc0ecf9264.filesusr.com/ugd/fe0276_a793888ab753487bbb0bb11ba753e8eb.pdf?index=true
- https://s3.amazonaws.com/zonebon/paraphrasing_exercises_with_answers.pdf
- https://s3.amazonaws.com/ditiruz/15411826021.pdf
- https://9df6e0af-a028-4e88-91ba-61a1b37318d5.filesusr.com/ugd/7c1f05_587e2fd8377c460194f4e47020c03b24.pdf?index=true
- https://3f9320ff-391d-49df-b192-c557e211a93c.filesusr.com/ugd/469aea_d3e3848d58724f4d8c44c1fe1111bde6.pdf?index=true
- https://s3.amazonaws.com/xidazeze/sutisopove.pdf
- https://07d68bf2-0661-47e2-9ffe-eae068a071af.filesusr.com/ugd/fef806_4809c3481c194d5f8dd293eead35f784.pdf?index=true
- https://s3.amazonaws.com/folexapurilowe/amman_songs_tamilwire.pdf
- https://s3.amazonaws.com/zagapaxa/pewenedawubutago.pdf
- https://810dce77-56ab-4324-823a-3549757f4eab.filesusr.com/ugd/1fad07_1cacdd0cebfe45c588f0dcdc8893a0e6.pdf?index=true
- https://2d2b1dae-c014-4902-97e6-c3f1d56915cd.filesusr.com/ugd/70e5f7_b9d73a5753d54dd5941a76820a4c68e3.pdf?index=true
- https://s3.amazonaws.com/nigimul/dovutet.pdf
- https://93dbb2ad-f1e8-4c6c-adfd-2ef134399473.filesusr.com/ugd/df4650_68bbf8991efc43efb1aafbd5a01c4286.pdf?index=true
- https://s3.amazonaws.com/donarepemi/los_mejores_cursos_de_ingles_cdmx.pdf
- https://ff5ab256-a407-4697-91b9-141751226614.filesusr.com/ugd/4205e4_48f924a686bb40febbd5390b9914a45a.pdf?index=true
- https://181f3bdf-810f-4c34-abb3-9f3362228cd6.filesusr.com/ugd/30415f_375e6cb237de4b07a7abb0fc1a904a56.pdf?index=true
- https://08b4a39d-fa16-4eaa-91be-ae90003cacb9.filesusr.com/ugd/237bf7_c254e2d11d5e43edb47d9e9955f19c84.pdf?index=true
- https://s3.amazonaws.com/zesotat/frame_size_guide_glasses.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00012180.binca2f746bde12420042a0cab6159b1f1a6092891b45f55f90974b9d66769ba3de |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12180 | 5336 bytes |
font_01_sfnt_off00013395.bin36f7c9ecf1b782b12f96eb7a5156c48dd03355ab528e2d2953e61a2c07b4e0eb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13395 | 11344 bytes |
font_02_sfnt_off00015a13.binb50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15A13 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.