MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, with one prominent heuristic identifying it as a 'PDF_SEO_LINK_FARM' containing 30 external links. The document body, though heavily obfuscated, contains a question about teacher salaries in Texas, suggesting a lure to phishing or spam content. The presence of multiple unknown reputation URLs further supports this malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://seumenha.ru/strik?utm_term=what+is+the+average+pay+for+a+teacher+in+texas
- https://cdn.sqhk.co/bamosabubesi/Ija2OEe/pupepewedutoz.pdf
- http://tk-time.site/mushtaq_biochemistry_vol_1x35sh.pdf
- https://cdn.sqhk.co/xapejinogum/jjf2sgf/barbie_doll_cake_design_images.pdf
- https://cdn.sqhk.co/xajevedu/g70ZL6I/japanese_anti_aircraft_cruiser.pdf
- http://gramnews.xyz/terapi_cacar_airl56t9.pdf
- http://uscreditcheck.info/zoruxejokomidugetex1hvje.pdf
- https://cdn.sqhk.co/revikokelobu/giv5qjb/kakikufanasimijem.pdf
- https://cdn.sqhk.co/temirikuji/jN7hjmi/ruxirupu.pdf
- https://cdn.sqhk.co/valujoper/shjdUjc/tiny_army_i_created_myself.pdf
- https://cdn.sqhk.co/fuzomorikat/BujhgwF/binary._com_bot_xml_2019.pdf
- http://helplnstagramcontact6088757.com/guerra_de_guerrillas_y_ejemplosk7esc.pdf
- https://cdn.sqhk.co/mafowixodi/5hhieBM/53091884299.pdf
- http://lnstagramverifiedsbadgeform.com/what_is_organizational_culture_articlesl60li.pdf
- http://grizhoff.ru/pixunumogawipajuuqj3p.pdf
- http://ukrinsure.com/83146075856hxn65.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://9c12218e-e157-4070-b33f-4467b3cb42bb.filesusr.com/ugd/0c60a0_aca8e18e8b66498b81072f3b13614d10.pdf?index=true
- https://ef5e9b3f-1a8e-4c79-9b60-34b8f8133c96.filesusr.com/ugd/18574e_20a04b7bd55b4fcfa95a019efc910a93.pdf?index=true
- https://b1b1ed1d-a631-407f-b8a0-2f609481a9c2.filesusr.com/ugd/3e5895_07bf059e83aa4df6a9659add05dc7d5d.pdf?index=true
- https://96ea5dd8-6962-4d57-b29c-fb233a715e3b.filesusr.com/ugd/ac3463_09316d4e32da49598743b17d996bb95f.pdf?index=true
- https://945c5b1a-9feb-4a08-b72d-c905ca1b1520.filesusr.com/ugd/27135d_f6680602c69f486ea5c264917000ff01.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fcf1.bin21d1a37a6a6b3a112ebfd54822fd19f5d95ac7868cb170c649e3d4bd62b4ab2c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFCF1 | 5488 bytes |
font_01_sfnt_off00010fbb.bin77ceabb21ab2ebf11b8ea66caf828f56097c87e3e06890b0e8e4ef71c3f42b6a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10FBB | 11128 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.