MALICIOUS
236
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
The PDF contains numerous external links, with a significant number pointing to Weebly domains, suggesting a link farm or distribution network for malicious content. The 'Advance-fee lottery/parcel scam lure' heuristic indicates a phishing or scamming attempt. The presence of 'cmd_commands_list_files.pdf' and associated URLs, along with the ML classifier and ClamAV detections, strongly suggests malicious intent, likely involving the execution of further payloads or redirection to phishing sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 7
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/123?utm_term=bleacher+report+football+live+stream
- https://golotarati.weebly.com/uploads/1/3/1/8/131856611/1ae0ef793ec6.pdf
- http://weraka.online/zawawivunidw5oja.pdf
- https://limofagis.weebly.com/uploads/1/3/4/6/134640762/4872039.pdf
- http://sale50.pro/adobe_writer_for_windows_10nhgfs.pdf
- https://buvekidi.weebly.com/uploads/1/3/0/7/130775196/a4cab16780124bb.pdf
- https://guvepilafofifiv.weebly.com/uploads/1/3/4/6/134682232/3311abb2fd89.pdf
- https://xudidetopos.weebly.com/uploads/1/3/4/5/134579215/ruxivajosa-gerixoxexefi-javinokuruxude-zegipepuni.pdf
- http://prizinsta24.space/96190160609f8qdl.pdf
- http://reduslim-italy.site/89281167102nu1zd.pdf
- https://xumodaniteged.weebly.com/uploads/1/3/4/4/134480563/6d759c38230.pdf
- https://xowasesulozuvuv.weebly.com/uploads/1/3/5/3/135347394/wewapi-milidiso.pdf
- https://xumodaniteged.weebly.com
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/ee07b627-990a-4c17-9e8d-02b7da19a582/79230129723.pdf
- https://s3.amazonaws.com/gixawetopoli/introduction_to_law_and_the_legal_system_11th_edition_download.pdf
- https://4454cc88-256b-48ad-9013-c0414c72072d.filesusr.com/ugd/67e251_69700448ced142c2a0bb7538096c90fc.pdf?index=true
- https://s3.amazonaws.com/jeduzizonox/85403085607.pdf
- https://5e3b32e6-a537-4a58-a531-ef303a468713.filesusr.com/ugd/120874_ea63e24239b14e4980262712817587a3.pdf?index=true
- https://c6f55193-7475-4343-97dd-33cb3b141b6a.filesusr.com/ugd/808d8c_332006ab9f5e48479534e29135a63612.pdf?index=true
- https://abaaaae4-9231-44fc-b12c-ad55ebcc68e7.filesusr.com/ugd/2ca09c_933a2ce863c64c6eb2ae1c5f36cd4a87.pdf?index=true
- https://uploads.strikinglycdn.com/files/005fda67-4e09-4e8c-9330-f3aeb735493d/basic_guitar_chords_finger_placement.pdf
- https://uploads.strikinglycdn.com/files/8cb80cf7-a0e9-40a5-a73d-655f9613772c/windows_cmd_commands_list_files.pdf
- https://95043331-d9de-4498-ad98-35b8ac3ee23f.filesusr.com/ugd/5740b2_5e9849b9e46b43859bef9865eccb6024.pdf?index=true
- https://uploads.strikinglycdn.com/files/8e2d773a-3403-452f-aadb-5b9fdc4ea6f8/72071390228.pdf
- https://s3.amazonaws.com/xedewofuretujo/what_was_the_central_theme_that_enlightenment_thinkers_were_writing_about.pdf
- https://uploads.strikinglycdn.com/files/5b17f533-d2c2-4375-a407-1835f52a3332/3193130627.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000eeae.bin42e8bcb6d98861b8d70c6b638821aa8d620371dc5b0a84986d58cacdf78b2a16 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEEAE | 5504 bytes |
font_01_sfnt_off00010141.bin79e0086d5c95bde1ef9cc55156b5924122946e2d505b630458b3e7be73fc79db |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10141 | 11268 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.