MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with one prominent URL pointing to 'jacksth.ru', suggesting a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of a malicious lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/strik?utm_term=brother+hl-l2360dw+wireless+setup+mac
- https://cdn.sqhk.co/makulowujip/z1XjijB/bemajewivaguliketibuzom.pdf
- https://cdn.sqhk.co/wifopuzuxiba/k1fjghh/vidmate_all_downloader_2019.pdf
- http://xagakojitogiva.getenjoyment.net/wuzigudod.pdf
- http://xepidenad.scienceontheweb.net/john_deere_750_tractor_front_weights.pdf
- http://dosaxixapaxa.medianewsonline.com/76877946015.pdf
- https://cdn.sqhk.co/zamikukodef/Dgdhgii/photo_music_video_maker_app_download.pdf
- http://fuwijumazawad.mywebcommunity.org/abatement_in_service_tax.pdf
- http://dinewegivogofe.mygamesonline.org/88412343159.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.fontrix.comhttp://www.nhncorp.com
- https://df256b98-640c-444d-885a-8195c7360722.filesusr.com/ugd/40b9e6_5dde4e5eeacb45da9852cd9813f654d6.pdf?index=true
- https://uploads.strikinglycdn.com/files/15840360-1f05-48de-ae97-cbcd7e829561/77801283301.pdf
- https://uploads.strikinglycdn.com/files/81ae43e6-5d67-41cd-81c9-43fe2f502635/merezejege.pdf
- https://83d12552-0bc1-4415-b221-1da25caacb9b.filesusr.com/ugd/1e11d0_e4fcc7644abe410589327d766bcf184a.pdf?index=true
- https://204833c8-abda-4421-8777-5048ee7dd919.filesusr.com/ugd/e30b7a_a26f11adc9a143ff81945f5f2208bcf5.pdf?index=true
- https://uploads.strikinglycdn.com/files/16e6fd21-54f6-449c-b7eb-5ec5605c7f96/navy_seal_foundation_charity_rating.pdf
- https://uploads.strikinglycdn.com/files/dc434d3d-0714-4125-acb4-3fc92ee43aa1/lukufasanafesubepegekalik.pdf
- https://uploads.strikinglycdn.com/files/b4251914-903f-4e6c-929d-623dd44535f2/el_arte_de_amar_michalina_wislocka_libro_gratis.pdf
- https://1c896d37-30d1-4b4d-9537-98f963aae812.filesusr.com/ugd/865d50_aeccc484653b45a5934f58ebce75dbb6.pdf?index=true
- https://uploads.strikinglycdn.com/files/3c400588-6d18-49a4-8987-f47537062ac4/21746002029.pdf
- https://uploads.strikinglycdn.com/files/bc5c1454-82b7-4f30-b2a4-0baebac64f2f/25098283928.pdf
- https://50aad03f-9d2a-47e6-be13-abd12f321b17.filesusr.com/ugd/3fd638_51235e214a444153952d74cb5b9f26e8.pdf?index=true
- https://uploads.strikinglycdn.com/files/e71288a7-162d-457a-9df5-999d19f8a9e3/how_to_breathe_better_during_exercise.pdf
- http://viniwowosur.onlinewebshop.net/rijuvakok.pdf
- http://raxegujanamefas.atwebpages.com/what_are_the_different_types_of_manufacturing_process.pdf
- http://kexomun.myartsonline.com/kitekofusasovoje.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ebf6.bin3b605d9914cd97a906d896923ff954376be7a1fa2f2fa4bf0d4769944c3a846c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEBF6 | 6076 bytes |
font_01_sfnt_off0001008d.binef5f279e139d95b9ae40058dd7e8cbbd437553bf97cb895690b456717162db09 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1008D | 11172 bytes |
font_02_sfnt_off000126c1.bin7be423a9975dd74696fa28cd46b52a55c3739f4a885228df3b07ea410fd2731b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x126C1 | 2056 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.