MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafftec.ru/strik?keyword=minecraft+enchanter+ftb PDF link annotation
- https://kokexofagisukop.weebly.com/uploads/1/3/2/7/132710589/9898268.pdfIn PDF document text
- https://kukevukoleguko.weebly.com/uploads/1/3/4/2/134265740/15c59.pdfIn PDF document text
- https://rajaxamakato.weebly.com/uploads/1/3/2/3/132302926/gafajifinime-lavodefikav-dilutitibol-nogunajizanug.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/b14aab5e-e3c1-4928-aa83-f8be40f22742/nuevo_testamento_interlineal_griego_espaol.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8aaa6f8a-e6b1-49d3-8895-302fa01d1d7a/pcms_drama_club.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ba9c1074-f54f-451c-8313-3fac4fbdb896/95231601456.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3cd2b989-0df6-48c3-96ca-df5bc7dcecdb/neben_mir_ist_noch_platz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fa462341-6b44-4e2c-b408-e11bb0eaab84/sfusd_calendar_2020.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6a1a0742-312e-4548-99ca-86f9a230bdda/pudexegi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9297922f-0e3c-4f0b-8a75-501fab2f2b7f/zatiwoxe.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c96f1905-bb2f-455e-a069-808e386bcad6/21904791124.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a5fd197e-2119-45d6-a53b-13660beba638/10929017296.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7acc90f5-2222-4f39-aebf-448dc730a886/48582846151.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/48894389-c543-4347-99cb-e339fb5825a9/liwibalijegajajajad.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cba9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCBA9 | 4904 bytes |
SHA-256: 09baea805eef79ba86c14daf8b4310b21adce0d72569c1f4d1dc17060538d5d8 |
|||
font_01_sfnt_off0000dc63.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDC63 | 10472 bytes |
SHA-256: b4b77f03f34f97aa511532748127aeb8c3ea4b0c989914229fb002e67f960916 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.