MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://allytemp.ru/pbw?utm_term=lulubox+apk+free+skin+mobile+legend PDF link annotation
- https://cdn-cms.f-static.net/uploads/4446174/normal_60bb2bc54f37f.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369794/normal_60bd90627d4fc.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4389599/normal_6060bd443e09e.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4393361/normal_6054dc0019cbe.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4457861/normal_60bd973f3bd4e.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4457847/normal_5ff463237af34.pdfIn PDF document text
- https://bagonapibuvuxo.weebly.com/uploads/1/3/0/7/130738628/vudutubazuwet-xaravugosat-siwawub-kovunowazine.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4480142/normal_604ed046e6445.pdfIn PDF document text
- https://sozakipebi.weebly.com/uploads/1/3/0/8/130814717/259898.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4372737/normal_6044d5f77b28b.pdfIn PDF document text
- https://bupifepubeweta.weebly.com/uploads/1/3/4/3/134336259/761cca09b3bb.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4404514/normal_60464cf0b72b8.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/1bd695b6-5b55-4605-a67c-0d98f83627f6/nutrition_through_the_life_cycle_word_search.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5e9708b3-416f-474a-8f3e-68ba8b179c03/what_attachments_fit_husqvarna_128ld.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b3fe3bc0-b587-4b53-acec-ca022176fde0/pst_jst_jobs_in_sindh_2021_uc_wise_list.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0228f7b3-ce80-4d89-a653-27642d2e4fdd/89048826176.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6b7e78be-5525-448d-b13f-340d80a26241/hp_officejet_pro_8500_premier_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/31dcd617-e4b7-4f9a-9743-1a3dd1f6d229/robert_kiyosaki_books_bundle.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fd14ddc9-2efe-4adf-adef-2c4505f39e7f/company_of_heroes_2_cheats_instant_build.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/84bbdf3e-4c9c-45dd-9a80-9110e30fc213/cheat_gta_v_ps3_tsunami.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7f8e9cf1-35e6-41fc-9ea0-6ac47d7f8761/how_to_name_a_story_book.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/44bfb868-a1d0-4eef-8b8c-4a78cd28e707/nikupiv.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000da81.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDA81 | 5576 bytes |
SHA-256: ebb76c61db8f10537b1c63131796f6f2e27ec8fac592f0ba11442f1de93251e7 |
|||
font_01_sfnt_off0000ed6a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xED6A | 10184 bytes |
SHA-256: d60bfe5522295fc54bd36f45df8fcb3b913450cc2d0391858415a0e9c5991749 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.