MALICIOUS
226
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document is classified as malicious by ML and ClamAV, indicating a high likelihood of malicious intent. It functions as a link farm, directing users to various external PDFs, one of which is hosted on disposable infrastructure. The heuristic 'SE_PASSWORD_ARCHIVE_LURE' suggests the document's purpose is to trick users into downloading a password-protected archive, a common tactic to bypass security scans. The presence of embedded URLs further supports the phishing and malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://medvor.ru/pbw?utm_term=download+gta+san+andreas+obb+200mb PDF link annotation
- https://static.s123-cdn-static.com/uploads/4486061/normal_5fdfbe1f98ab5.pdfIn PDF document text
- https://jipunone.weebly.com/uploads/1/3/5/3/135349916/8131402.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4421637/normal_5ff07fb08d4c3.pdfIn PDF document text
- https://togawikanow.weebly.com/uploads/1/3/5/3/135320583/gafulume.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4503767/normal_600ff20a729ec.pdfIn PDF document text
- https://wafodefa.weebly.com/uploads/1/3/4/4/134480145/migizawewikuwutogijo.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4385869/normal_6062f10ee8d58.pdfIn PDF document text
- https://static.s123-cdn-static-d.com/uploads/4458431/normal_60aff2a1d9745.pdfIn PDF document text
- https://bezujaseda.weebly.com/uploads/1/3/1/4/131437953/c48058bea83b1f0.pdfIn PDF document text
- https://sifoginugiji.weebly.com/uploads/1/3/4/5/134588619/a5fbda.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/ac81eb83-538c-4f69-8e65-913dbc1da253/nexus_9_android_10_update.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7a2b4652-eadc-4036-abae-23e63de4c463/sufutaderaguzoluvizigutir.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ee08da6f-5b09-4e78-95f6-f67cc0b16970/sojegojawokugurivalut.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ad48cf52-fd5c-42b6-a5a7-cb48438c9566/vevurusanilula.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/25eb29c2-4626-4a2f-a077-b9f6a6e43bcf/gym_workout_routine_muscle_gain.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e839fd55-10a7-4468-ab46-656841ac90d1/how_to_get_a_fork_truck_license.pdfIn PDF document text
- http://pokuwatosat.pbworks.com/w/file/fetch/144555702/88498762130.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/48ea8a55-e697-4612-adf7-b82cbfefbdcb/27859694648.pdfIn PDF document text
- http://liwuvedesisu.pbworks.com/w/file/fetch/144578643/23055763020.pdfIn PDF document text
- http://feselikebapu.pbworks.com/w/file/fetch/144891699/ssf2_0.9_b_unblocked.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3d21946d-c27a-4604-9d26-81ad230962fb/36136785743.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4a3d4c9b-4c31-4be7-b2c1-4bce2f17567a/mixinopejerojumeweremole.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/99b28bc1-033d-4521-8181-e55597f84891/sulawupenatirujupumisojof.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/33991294-d9e8-44d3-8f8b-061c76bcb1e7/what_are_the_key_components_of_realism.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dc19.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDC19 | 5648 bytes |
SHA-256: 80dafef6d538c6abb7183a0abd2817ba33ca03f096eb46bb5ca5433255cc14c7 |
|||
font_01_sfnt_off0000ef56.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEF56 | 10440 bytes |
SHA-256: 75670bdd3ae24611ab9ff777835149f5d702f0024bc678699c32300b4dc4f93e |
|||
font_02_sfnt_off00011372.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11372 | 17112 bytes |
SHA-256: 2699f2ce65472362c7cce2649b9a1ca315f2f35cd4c84f2de76f8c9cc61a5f56 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.