MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jottigo.ru/wix?keyword=insanity+meal+plan+calendar PDF link annotation
- http://businessoutsourcing.org/bazuwuriv47itr.pdfIn PDF document text
- https://kunoloxudiruk.weebly.com/uploads/1/3/4/7/134767428/busosetilapevutonob.pdfIn PDF document text
- https://kipamafulu.weebly.com/uploads/1/3/4/5/134588126/sebotok-fovazanixotef.pdfIn PDF document text
- http://kinemulawaw.sportsontheweb.net/cell_organelle_worksheet.pdfIn PDF document text
- http://ropixasit.22web.org/catalogo_bticino_living_light.pdfIn PDF document text
- https://tozakewa.weebly.com/uploads/1/3/5/3/135398337/6ecfefb1f8b.pdfIn PDF document text
- http://kellys.space/lofudedozodegobetonapovadgauhh.pdfIn PDF document text
- http://rafupofamurawaf.mygamesonline.org/63284623600.pdfIn PDF document text
- http://frankiearvelo.com/rufus_wainwright_hallelujah_piano_sheet_music9ih8u.pdfIn PDF document text
- http://ourfanz.com/46321808575ci2vh.pdfIn PDF document text
- https://wunebometa.weebly.com/uploads/1/3/5/3/135314425/jaduwapa-zodinexol-rezomusega.pdfIn PDF document text
- https://lopenedaxi.weebly.com/uploads/1/3/1/6/131606218/poworepe_watisafebifoke_golilunizeleroz.pdfIn PDF document text
- http://nutetuxiv.mygamesonline.org/calibration_of_pressure_gauge_lab_report.pdfIn PDF document text
- http://uabiomanix.xyz/14781084132785ct.pdfIn PDF document text
- http://gesofetol.iblogger.org/holistic_nursing_approach.pdfIn PDF document text
- http://petrol-v-pol-price.site/history_of_speaking_in_tonguesk0gs0.pdfIn PDF document text
- http://sellamorem.com/25757156454z7mcm.pdfIn PDF document text
- http://raifaisentgo.online/ruzibinbuw3i.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/a1edafcd-8661-4d58-b2c7-42646c7f2997/20347194081.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/23ca65a7-5409-41d2-af6f-bb1a374f8806/67813721077.pdfIn PDF document text
- http://pizibajavodup.epizy.com/how_to_fix_a_dripping_spigot.pdfIn PDF document text
- http://lotidasifiteg.epizy.com/jumeruk.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ad59cd2b-924c-4867-ab31-3704e65fbf4e/sundance_optima_850_circulation_pump.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cb5b9827-b88b-4aa3-859f-8fad17291935/toro_snowblower_parts_primer_bulb.pdfIn PDF document text
- http://mugoguzof.rf.gd/79547452110.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f145.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF145 | 5256 bytes |
SHA-256: 2bf029d4694c50f61e2f103e9bd04cc6710dea21d580a9b6a313237b4ad4ec59 |
|||
font_01_sfnt_off00010315.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10315 | 11376 bytes |
SHA-256: 1fd5d7dad20e67281febbae2886c2b5b82f59b9cda8a53fb83c2ca2a51a3fc2b |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.