MALICIOUS
214
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous links to external websites, many of which are hosted on Weebly and appear to be part of a link farm. One critical heuristic indicates the PDF links to known malicious redirector infrastructure. The ClamAV detection and ML classifier further support its malicious nature, classifying it as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/strik?utm_term=asics+see+through+swimwear In PDF document text
- https://muxosafexokole.weebly.com/uploads/1/3/4/4/134485240/ee1bb4ed.pdfIn PDF document text
- https://ragurukenawuxif.weebly.com/uploads/1/3/4/6/134667210/gapulute.pdfIn PDF document text
- https://ferowadamo.weebly.com/uploads/1/3/4/5/134593689/mupozusoji.pdfIn PDF document text
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/7439702.pdfIn PDF document text
- https://wekonopu.weebly.com/uploads/1/3/4/8/134848362/bd89436b8a40.pdfIn PDF document text
- https://mivubifazexaj.weebly.com/uploads/1/3/4/3/134381565/5143981.pdfIn PDF document text
- https://kuzaloxamuw.weebly.com/uploads/1/3/1/4/131406684/lixiwijepavo.pdfIn PDF document text
- https://sawalodisixujig.weebly.com/uploads/1/3/4/4/134490012/tedosudopebolowus.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://static1.squarespace.com/static/5fc64f519955c744b5603647/t/5fc6ca2c48d5672cfb29eb7b/1606863404931/84929521987.pdfIn PDF document text
- https://static1.squarespace.com/static/5fceff5d181af13ce2744de0/t/5fd2206c5e090321cabb6566/1607606380992/the_lightning_thief_musical_original_cast_recording.pdfIn PDF document text
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe0fe361e25426e1007b16/1606291427433/xfyro_xs2_manual.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc77f0702915d4a16f8d210/t/5fd18cc4ce71ee580fa42854/1607568582974/lubobekutanakuretike.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/11d8aa73-9ec6-4b93-b9fa-b1615911817f/63219632747.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc0f27ea13a450babf44921/t/5fcefbdc3fa051062b3c9bcf/1607400418666/guess_the_amount_of_candy_corn.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ee439a6b-3007-455f-9966-4d44ed6e3011/kinetic_energy_problems_worksheet.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ad1e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAD1E | 5264 bytes |
SHA-256: c05d7d7e533e6b25bfd7ead148f6c1f893a3fa32f857b391163773b3b54a21f1 |
|||
font_01_sfnt_off0000beea.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBEEA | 9528 bytes |
SHA-256: 66aff159438fedd05f5ab03f2286a75aee40382c7e8a064bb913fc31de3e695a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.