MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains heuristics indicating it is a link farm and has been flagged by ML classifiers and ClamAV as malicious. The embedded URL, 'https://xezojetit.ru/123?utm_term=cable+needed+to+connect+android+to+tv', is likely the primary lure, attempting to trick users into clicking it under the pretext of connecting an Android device to a TV. No scripts were extracted, but the PDF structure and external URL suggest a phishing or redirection attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/123?utm_term=cable+needed+to+connect+android+to+tv
- http://dalkomis.website/carbon_dioxide_co2_has_what_type_of_intermolecular_forceswhykf.pdf
- http://salea.site/9177772859443wia.pdf
- http://nibajafij.medianewsonline.com/controlled_drug_delivery_system.pdf
- http://copyrightshelpscenters.com/1296951101ckyab.pdf
- http://timurberg.ru/17754168819agmnm.pdf
- http://zisezamerares.mygamesonline.org/avram_noam_chomsky.pdf
- http://voicebftyi.com/technivorm_moccamaster_59616_kbg_10-cup_coffee_maker_40_oz_polished_silvertjgan.pdf
- http://itasda.online/japefidoputezeguvavodaj6pe6x.pdf
- http://fullhp.info/mcp61pm-hm_nettle3_bios_updateffq8i.pdf
- http://bluebadge-support.com/85263591245nehz8.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/voxipanovigepiv/bonding_in_boranes.pdf
- https://9480ebe7-8096-4165-94d5-b35dd525e9f4.filesusr.com/ugd/07b43d_d7a7db50e892411a984261be8eee4aa9.pdf?index=true
- https://s3.amazonaws.com/kukazowox/47367738430.pdf
- http://dijipola.onlinewebshop.net/toefl_reading_test_sample.pdf
- http://guwaxilajoxeza.onlinewebshop.net/tovewojebetonelimiwovad.pdf
- https://b1c30c75-ab46-439a-884d-3836ae4b8a49.filesusr.com/ugd/2d1648_1beb54990fc94efc8f7236db2ddaec7a.pdf?index=true
- http://lewomunenuvi.myartsonline.com/10720887369.pdf
- http://senesijosezetu.myartsonline.com/how_to_port_sim_vodafone_to_jio_online.pdf
- https://s3.amazonaws.com/tuxenipup/boogie_down_productions_criminal_minded_zip.pdf
- http://limoxukuk.atwebpages.com/2004_6.0_powerstroke_engine_wiring_harness_diagram.pdf
- https://s3.amazonaws.com/fojaxexino/magidizukot.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f57a.bin7c5eaae5a6aa0e72d8f1eb99eb8d2d6207253b810fb428efb4c7ea37e29033c3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF57A | 4860 bytes |
font_01_sfnt_off0001060d.binae9ecbdf7291c1d58f3a88c108bbc0959443cc0c7e3f9dced28c3f689631c0c8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1060D | 11040 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.