MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.7521
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://baarspo.ru/strik?utm_term=the+wicket+gate+kingdom+come+wiki PDF link annotation
- http://lnstagram-help-businesss.com/ranekijubumanofixuteruruw9z8s.pdfIn PDF document text
- http://befelofote.iblogger.org/75577737343.pdfIn PDF document text
- http://wide-take.top/496465833773embb.pdfIn PDF document text
- http://baliferifopiz.mypressonline.com/prehistory_dk_bhattacharya.pdfIn PDF document text
- http://cmbclientes.com/english_grammar_tenses_rules_in_urduh4q3z.pdfIn PDF document text
- http://itdiscount.pro/introduction_to_node.js_pptchkko.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://fedorahosted.org/lohitIn PDF document text
- https://s3.amazonaws.com/pavujiniz/information_architecture_template_document.pdfIn PDF document text
- https://s3.amazonaws.com/tarizirefevifab/merrill_lynch_mortgage_investors_trust_series_2006-sl2.pdfIn PDF document text
- https://s3.amazonaws.com/rijaliwiguvex/74168510790.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a0a95172-c7fe-4d06-af4d-96d48e356805/how_to_write_a_dateline_in_ap_style.pdfIn PDF document text
- https://931f52e6-cb68-4a93-8e02-54808d33f8b6.filesusr.com/ugd/6290de_a972a8d3cab349d985b60f9883c9c7af.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/9f4caa3a-3394-45aa-845c-2323797932a6/30565953712.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f63ff6f0-370d-4f5b-8510-2a61fd0794c9/kuwozuvozido.pdfIn PDF document text
- http://kopolug.myartsonline.com/55995085992.pdfIn PDF document text
- http://zezogif.rf.gd/sweatcoin_apk_mod.pdfIn PDF document text
- https://s3.amazonaws.com/mexesazaxasa/what_causes_discolored_front_teeth.pdfIn PDF document text
- https://b9387e75-0942-48a6-8a47-0bd3f0224277.filesusr.com/ugd/fc485c_ce03a8e5919549ffbe8e864984ca8038.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/panalipolifod/bezijakudugal.pdfIn PDF document text
- http://getapumofibejop.epizy.com/christmas_song_back_number_instrumental.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/40d29ab4-3f2d-432d-9b61-49a203a0f3ed/nustep_trs_4000_specs.pdfIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00014996.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14996 | 5152 bytes |
SHA-256: 25be49c58d3927fd25263a05abcfb3692d890289ec6b9560ed631c93dae3cc04 |
|||
font_01_sfnt_off00015b0a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15B0A | 4928 bytes |
SHA-256: e5c329823baf740f6a3f9138bec909fe5fbfd5b437205cac42e42c40cd8afda5 |
|||
font_02_sfnt_off00016bff.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16BFF | 12292 bytes |
SHA-256: 6500957fa889242f7129fb610386ea97fbb5879574412e3b1edf5316214e851d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.