MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of external links, with one heuristic specifically identifying it as a 'PDF_SEO_LINK_FARM'. The ML classifier and ClamAV detection strongly indicate malicious intent, classifying it as a phishing trojan. The embedded URLs suggest a redirection mechanism to potentially malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://leonvi.ru/wix?keyword=it+essentials+chapter+5+study+guide
- https://cdn.sqhk.co/xeloxilava/uhbooGR/pba_tour_bowling_2019_tv_schedule.pdf
- https://cdn.sqhk.co/redusebi/iimiapd/jufusenowulojaxosanaxeje.pdf
- https://cdn.sqhk.co/wepurodapike/hbFhiLn/49748271872.pdf
- https://cdn.sqhk.co/navimoxa/hbJuGBB/kilidezosojasewi.pdf
- https://cdn.sqhk.co/putomikoluku/h5Sgjhb/satizoxufad.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://fc060a1e-8c1d-4b7d-bafd-75f79d4c6355.filesusr.com/ugd/c0a468_ed13022802c34e99adebb4a0621ac1de.pdf?index=true
- https://uploads.strikinglycdn.com/files/4e0498b5-3c07-4e60-bcd6-854cc29972ab/girudowat.pdf
- https://uploads.strikinglycdn.com/files/cbf6b0e9-8ad9-48d4-ab02-f165e3e2b469/62271518163.pdf
- https://uploads.strikinglycdn.com/files/924be6c4-e779-4c66-87a0-75a29558ee72/94020356762.pdf
- https://3e021c9a-284a-4c54-9ba1-f6d43d4d2ba5.filesusr.com/ugd/a619af_79ffee9dbb1c4d6ba7562b57bf5e3f77.pdf?index=true
- https://uploads.strikinglycdn.com/files/d55d58f5-e1e8-4bc6-b4b1-426cc7a2ceb0/are_lg_stylo_5_good_phones.pdf
- https://s3.amazonaws.com/juvetaso/problem_statement_template_slide.pdf
- https://uploads.strikinglycdn.com/files/50f029a0-1c12-44d9-8f9a-4b10a49eb5de/mibafaxifatisowaz.pdf
- https://uploads.strikinglycdn.com/files/da287479-b6e8-4df7-a695-c6391e2b936e/how_to_clean_maytag_bravos_xl_washer.pdf
- https://d5e9a058-cbdc-4968-ba72-30cdbf1e36a3.filesusr.com/ugd/9cfd0a_4fe2915d7c9242e0b565544d7c1c689e.pdf?index=true
- https://083189c9-8220-4687-a375-57be19a37228.filesusr.com/ugd/909b15_47ff637ced634a238dcc0eaab00c89e1.pdf?index=true
- https://uploads.strikinglycdn.com/files/641f66a0-3ff6-40aa-9ea7-02858d4d3b33/fitijesenojarofadozitubix.pdf
- https://uploads.strikinglycdn.com/files/4acb7e5b-04e0-4da3-9585-0e6a061b5684/what_is_the_order_of_the_amory_wars_books.pdf
- https://s3.amazonaws.com/kefiperizonofu/guided_journaling_for_depression.pdf
- https://uploads.strikinglycdn.com/files/d8e7dd02-d86a-4321-a75b-6eb27df7cb43/mini_dv_camcorder_player.pdf
- https://s3.amazonaws.com/votubukaxogilix/52025912974.pdf
- https://72cee60b-533f-4fda-9f40-87b1bb6f0553.filesusr.com/ugd/590778_259ba465a0f64807859c718d881bd4ac.pdf?index=true
- https://s3.amazonaws.com/zuvovoxigumuz/vuzoxa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fe0a.bin58d26081721f87a3b864061d6a2dada99388d62f440e726cce3c707e4d246ecd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE0A | 5268 bytes |
font_01_sfnt_off00010fe5.bin6fd8ec3fe425d4c251d48826132f2808598b3fae6c923fcd3a8a0c673553009a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10FE5 | 11584 bytes |
font_02_sfnt_off000136a1.bin1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x136A1 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.