MALICIOUS
186
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The PDF contains a large number of external links, many hosted on disposable domains, suggesting a link farm or SEO manipulation tactic. One of the extracted URLs, 'https://midufefew.ru/wix?keyword=choosing+grains+worksheet', appears to be a primary lure. While no scripts were explicitly extracted, the PDF structure and link farm behavior are indicative of phishing or malware distribution attempts.
Machine Learning
- Nyx PDF Classifier malicious score 0.9952
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://midufefew.ru/wix?keyword=choosing+grains+worksheet PDF link annotation
- http://ruxuruweluwi.iblogger.org/13_reasons_why_season_3_songs_mp3_download.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4417023/normal_602c05a96b5ab.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4365563/normal_5ffe295412c03.pdfIn PDF document text
- http://turosofatilez.iblogger.org/78404687675.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4476782/normal_602b77df5fa1e.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4415531/normal_5fd8f9c8acfec.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4500425/normal_5fe269bc47872.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4451374/normal_5fe859a1e68bf.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4458413/normal_5fd9a8e325f82.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4404108/normal_5fd60beea3c7b.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4475999/normal_5fe337853da40.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4410194/normal_600d48e05a5cf.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://vefagukolile.epizy.com/94477604578.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7592308d-5467-4dca-94f3-195dfc19633e/82069967297.pdfIn PDF document text
- http://botasalipigu.epizy.com/nec_advanced_analytics_platform_solution_templates.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5b0f38bb-05db-440f-9c9f-0bb86e106000/how_to_use_a_tempa_dot_thermometer.pdfIn PDF document text
- https://e97408dc-4b05-4e3b-9f19-f4127feb49ef.filesusr.com/ugd/a42eed_79828976285b41f9bf39f718f9c5f78f.pdf?index=trueIn PDF document text
- https://78905da9-dd21-4190-abaa-c894c042e703.filesusr.com/ugd/851c7c_e256b7dc373a4a46b3b4d2f496253038.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/5683f706-5660-4df7-8cdf-7dd54f154cc7/how_to_use_steam_clean_ge_oven.pdfIn PDF document text
- https://13ea8442-998f-4f14-ba3b-7f37e53a414c.filesusr.com/ugd/008a9f_3720db061e354976aedb2af08989f21c.pdf?index=trueIn PDF document text
- http://gudagugagazof.rf.gd/74082951121.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0b2aea6f-18f6-4fea-84b0-0c8d4a451653/pitch_anything_chapter_summary.pdfIn PDF document text
- https://a49aa754-465e-4bbd-924e-b3d0e7b66bd4.filesusr.com/ugd/81d6a4_57e115e2d9324b22851f076a4f225466.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/c3b542c1-ecc1-4408-a4a2-f289fefcbb75/20427614938.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/518d7a8c-f6c2-43aa-9d21-f5c466c144a0/does_sat_math_2_given_formulas.pdfIn PDF document text
- https://f0d491a7-7d72-4eea-bbd3-72ad31f48a9a.filesusr.com/ugd/1acdab_db4ed58b4e244558b710b3088c83a91f.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00011ef2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11EF2 | 4976 bytes |
SHA-256: 82c6a011ee3b8f6f6085002a979dad9f2876b6ef373b330fb180f0bd18961a89 |
|||
font_01_sfnt_off00012fe8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12FE8 | 11356 bytes |
SHA-256: 468c41a6759fd81533dff0cc5e77087999c9063a1fc4fe3a4b47cdff441e8f0e |
|||
font_02_sfnt_off000156dd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x156DD | 16452 bytes |
SHA-256: 70910c3f157dffaa2a054d394904fab0505b6608f800f53ba54387c75c0d040c |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.