MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was identified as malicious by multiple heuristics and an ML classifier, with ClamAV detecting it as a phishing trojan. The PDF contains a large number of external links, indicating it functions as a link farm for SEO purposes. The primary malicious intent appears to be directing users to potentially harmful websites, as evidenced by the numerous extracted URLs.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://druttle.ru/wix?keyword=yaoi+on+crunchyroll
- http://appeal-ig.com/marantec_comfort_220_garage_door_manualf2dif.pdf
- https://cdn-cms.f-static.net/uploads/4392649/normal_606a457dea5b8.pdf
- https://cdn-cms.f-static.net/uploads/4419452/normal_601aa24387695.pdf
- http://about-central.com/75313527200lulb7.pdf
- https://cdn-cms.f-static.net/uploads/4422382/normal_605a8eaf7540b.pdf
- https://cdn-cms.f-static.net/uploads/4381102/normal_605abcf4607c6.pdf
- http://mail-autoscout24.net/route_101_traffic_reportcg4b3.pdf
- http://energierecrute-emplois.com/558599560269ivas.pdf
- http://abanca-electronica.com/computational_statistics_solution_manual54wna.pdf
- https://cdn-cms.f-static.net/uploads/4424991/normal_600d8703a1f05.pdf
- https://static.s123-cdn-static.com/uploads/4368956/normal_5fdfb01986f54.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://68a74d12-89ac-4a94-b826-09ad332a30bf.filesusr.com/ugd/1a0392_9f6e28fc795e42538f3016769a2f1214.pdf?index=true
- https://4eff3ec4-d147-45d1-be73-876d9e1d0019.filesusr.com/ugd/efb3f0_cf2e9cb97d374ef8b16955ddc2c53300.pdf?index=true
- https://a819be37-316e-4347-83bc-b067fb6953c8.filesusr.com/ugd/d5662a_9efa1141325c45d5bf6935a7366ecf6c.pdf?index=true
- https://s3.amazonaws.com/bepukuba/free_printable_periodic_table.pdf
- https://s3.amazonaws.com/kakekojezutok/limites_de_funciones_de_varias_variables_ejercicios_resueltos.pdf
- https://fefcf4f0-bf52-4086-adb3-b788df03f7bd.filesusr.com/ugd/da9d4c_57490623bae04ebcac040eeaa7ae7be6.pdf?index=true
- https://s3.amazonaws.com/vapite/truck_camper_loading_guides.pdf
- https://49432a94-54bc-4d13-9d12-ea41d731e1b8.filesusr.com/ugd/a7c689_1f0b36dd27e247dc8701d59a30ae8f1c.pdf?index=true
- https://s3.amazonaws.com/nuvukivaxiren/archangel_s_war_nalini_singh.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dbfc.bin8fe238d4efa118d1e805f072976fe3c461391de55fefcb4facfc8f71fb735506 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDBFC | 3016 bytes |
font_01_sfnt_off0000e6b7.bin2ab704168e821fafd21a86ba7dd3f6908fc7780880ef61e983ff0ef64aa05714 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE6B7 | 4772 bytes |
font_02_sfnt_off0000f6f7.bin8efc542c0fe29006fe3d854fe1b70f4662f3816643079524ffe5a82596e313e9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF6F7 | 10656 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.