MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, many of which are to potentially malicious domains, indicating a link farm or phishing attempt. The ML classifier and ClamAV detection strongly suggest malicious intent. While no scripts were directly extracted, the PDF structure and embedded URIs point towards a malicious workflow designed to redirect users to external sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ponafet.ru/award?keyword=pop+design+booklet+pdf
- https://cdn.sqhk.co/livixugakuf/xJjb7XM/giwumivobijarugejizapapaj.pdf
- http://it50life.pro/cool_puzzle_games_for_android_free7ulwl.pdf
- https://nodirerivono.weebly.com/uploads/1/3/6/0/136052085/0228f3d16e8c.pdf
- https://cdn.sqhk.co/kukisigafumi/eicRib6/movies_2019_action_thriller.pdf
- https://sorebupewuf.weebly.com/uploads/1/3/4/4/134447244/jafonip.pdf
- https://cdn-cms.f-static.net/uploads/4489050/normal_6046b89723606.pdf
- https://cdn.sqhk.co/zopimoforaja/jjfa6je/real_steel_movie_1080p_free_download.pdf
- https://cdn-cms.f-static.net/uploads/4462726/normal_60132fd731c4a.pdf
- https://cdn.sqhk.co/fufigavaki/c6vXidk/pubowani.pdf
- https://moredotaze.weebly.com/uploads/1/3/0/7/130776260/jewojededas.pdf
- http://ses-sanobrabotka.ru/24344433300rxce.pdf
- https://cdn-cms.f-static.net/uploads/4402936/normal_6040a57b235d8.pdf
- https://cdn.sqhk.co/lazujanaziri/rghfljc/digital_terms_synonyms.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/5ed2c2cf-7fb6-4844-a0d4-8c36e15abd78/pozozanupefudosamuj.pdf
- https://uploads.strikinglycdn.com/files/62ce5600-03a1-4363-b6d4-bebc2254f36f/nesokefusavipi.pdf
- https://uploads.strikinglycdn.com/files/1796ea27-5faf-4977-8c6e-195c81025282/samotuvupuxiwekopexu.pdf
- https://uploads.strikinglycdn.com/files/e95413b2-c9ee-4f43-b8de-9ccf8f4232ab/bitadoditoz.pdf
- https://uploads.strikinglycdn.com/files/23f2a6c5-8b55-4bde-ad9b-53213533cb66/86416330710.pdf
- https://uploads.strikinglycdn.com/files/599e12d1-0f9c-496d-9ca3-2c6205d08db0/how_to_use_hoover_steamvac_power_max.pdf
- https://uploads.strikinglycdn.com/files/1359eb31-5b85-4a29-bc5d-b1e5b0ca2555/how_to_print_a_free_birthday_card.pdf
- https://uploads.strikinglycdn.com/files/91107fbf-dcd1-48c6-a969-f3df10b12751/fifth_grade_math_worksheets_with_answer_key.pdf
- https://uploads.strikinglycdn.com/files/32d912f1-02b1-4af7-84b8-094d09850760/lolulosi.pdf
- https://uploads.strikinglycdn.com/files/6495d7b5-a43a-4892-a645-ff2915ce33c1/can_you_program_a_garage_door_opener_to_open_a_gate.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000db2e.bine4a421a80b5a45b1c0741397cabfa97e89bc96c49a13b67fed0bf66bf56c403b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDB2E | 5108 bytes |
font_01_sfnt_off0000eca9.bin5ab9a0e001f60b213cb4918cad95166fd1e8df0dd97067ac41a19472b26634fb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xECA9 | 10628 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.