MALICIOUS
214
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains multiple embedded URLs, with one identified as a malicious redirector. The heuristic firings indicate that the PDF is designed to link to malicious infrastructure and functions as a link farm. Although no scripts were explicitly extracted, the nature of the embedded links and the ClamAV detection suggest a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cctraff.ru/aws?utm_term=asbestos+awareness+training+certificate+template
- https://nefafege.weebly.com/uploads/1/3/4/6/134642137/bc6b40710a3df.pdf
- https://sakukavazu.weebly.com/uploads/1/3/1/3/131379729/9853851.pdf
- https://namoxatiki.weebly.com/uploads/1/3/4/4/134477177/bd18213b6ea.pdf
- https://cdn-cms.f-static.net/uploads/4425504/normal_5f986e310c617.pdf
- https://cdn-cms.f-static.net/uploads/4498978/normal_5fc27fe542915.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/nipomomuka_gisotufeje.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/9af1f15a-dee7-4eda-9b3e-6b1b59a47aeb/abnormal_psychology_textbook_free.pdf
- https://static1.squarespace.com/static/5fc5982e085bf90c0e1d0cdd/t/5fd15854fec2791e31f7a7a5/1607555163308/miners_settlement_open_world_idle_clicker_game.pdf
- https://static1.squarespace.com/static/5fc1015360f2895dc1e86a3c/t/5fc34e47e18c5c478e6583bd/1606635079923/tahini_san_diego_hours.pdf
- https://static1.squarespace.com/static/5fc14581c89e1c4b8fc0e725/t/5fc7fed20713b02bcaee868b/1606942420340/hungry_shark_evolution_games_free_download.pdf
- https://static1.squarespace.com/static/5fc066bd9955c744b5390948/t/5fc20e443570fb44d14a1a77/1606553157279/next_to_of_course_god_america.pdf
- https://static1.squarespace.com/static/5fc0ba3b0a2757459be1f9cb/t/5fc2be612dd96f591848b76e/1606598241558/weniwidesupusuwaxed.pdf
- https://static1.squarespace.com/static/5fbffb332bbd740658015355/t/5fc44151173fb5383b2a6323/1606697298598/manitowoc_county_jail_prisoner_list.pdf
- https://uploads.strikinglycdn.com/files/96813f03-16f3-4733-be16-040caff41c42/boxhead_hacked_unblocked_76.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d043.binf42d66cf7599570c3f0008505e385d53ef2a041228919a5adbdf3ff1db13ac91 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD043 | 5556 bytes |
font_01_sfnt_off0000e32e.binbd82982a93159ebade4971ac4e9f00344d68594f27fdf50e7a1008a27a39413e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE32E | 9808 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.