Malware Insights
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a large number of embedded links, many of which point to disposable hosting and are likely part of a link farm designed to redirect users to malicious sites, such as the one at 'https://crophysi.ru/strik?utm_term=you+are+a+badass+at+making+money+master+the+mindset+of+wealth+jen+sincero+pdf'. The document body appears to be obfuscated or corrupted, but the presence of numerous links and the malicious detection strongly suggest a phishing or scam campaign.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://crophysi.ru/strik?utm_term=you+are+a+badass+at+making+money+master+the+mindset+of+wealth+jen+sincero+pdf In PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://f7cac2f2-528f-490f-9bef-cb2448a877de.filesusr.com/ugd/529ba0_e81adfe1cdec4691bc00c4e6bfdb89e0.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/dosipive/what_household_cleaners_kill_ringworm.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4474bfb8-6317-4d98-baf5-4d18e4c1e404/tevopetokusoxit.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/54dec580-43bf-40cf-8ae1-dd9078705bc3/how_do_i_factory_reset_my_ipod_nano_6th_generation_without_itunes.pdfIn PDF document text
- https://f421159b-d329-41e8-bc42-072bc93e4c50.filesusr.com/ugd/65d6f7_b8d1194e0c7a4d6dbe1a97fc8a7acbf8.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/toguvaju/nexum.pdfIn PDF document text
- https://a7da3e60-63c8-46c1-a846-eab7df628ed2.filesusr.com/ugd/bba345_0a6eea997311477190d9c10973972b29.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/21564439-5534-494e-ada0-dac5a40f9891/what_does_it_mean_32_bit_operating_system_x64_based_processor.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/93e5ec4e-db96-4661-ac08-31d3287d4fa7/99664421579.pdfIn PDF document text
- https://37dcb74a-b492-4e6c-94d7-6984b04a3d7f.filesusr.com/ugd/01eaca_0b54c378132142719e57725a86e24cb5.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/1b04e32b-a287-483d-a7be-a9fe1433ece4/73932492428.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/69fb0de2-d2ca-420d-92d3-269c8c9c67e1/vitalurefusofomakinag.pdfIn PDF document text
- https://cd29ef07-728f-4a0b-b57b-23e770395c36.filesusr.com/ugd/f14cf6_72f8e5926f2846e5923daa8a8d324faf.pdf?index=trueIn PDF document text
- https://9387bd13-3746-4408-b474-2867f26e464d.filesusr.com/ugd/ace02d_61e9c13eff614320a27d980bbc1824c3.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/zizene/lanerurolipix.pdfIn PDF document text
- https://54a0e2cb-796f-4f80-9aaf-d11633176b06.filesusr.com/ugd/b0c554_c055f327a73b4cfc9c0417ccf9ef86b4.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/c965f11b-8f9a-47cd-904f-f96ba3cfb0e1/kenmore_quiet_comfort_14_humidifier_manual.pdfIn PDF document text
- https://s3.amazonaws.com/xalexojaxipud/best_air_conditioner_remote_app_for_android.pdfIn PDF document text
- https://58960a86-a3f4-42d8-866e-ee2cf32068b1.filesusr.com/ugd/1ad962_fa5f511d35d64217b1bd7c71c85811da.pdf?index=trueIn PDF document text
- https://26c1613e-5d28-4fa3-89cb-3d2c9ab59faf.filesusr.com/ugd/fe83c3_865ea177df5e4183a21df097d2089146.pdf?index=trueIn PDF document text
- https://c78ffd2e-fc3d-4272-86ca-968d835fb7ad.filesusr.com/ugd/0f9ef0_7b46796478024a82833dbc01479c7e58.pdf?index=trueIn PDF document text
- https://c0b8f06b-4e98-4d3d-89ef-2f08caba629a.filesusr.com/ugd/0c8cc8_e86f5ef728a74980acf72f30c89b5e5a.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e91a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE91A | 6004 bytes |
SHA-256: 1dd88606dcec954663e21beaa4af95590147d0a2173f3d050c3a9d861f3d68cc |
|||
font_01_sfnt_off0000fd82.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFD82 | 10868 bytes |
SHA-256: 7093354678aa9f3263ad2e4347cd8fea703000c04ba4b119e6eda50bb00d3802 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.