MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains a large number of external links, suggesting a link farm or phishing attempt. The embedded URLs point to potentially malicious domains, with one notable URL being `https://trafficel.ru/123?utm_term=large+breed+dog+water+dispenser`. No scripts were extracted, but the PDF structure and link farm indicate a likely attempt to redirect users to malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafficel.ru/123?utm_term=large+breed+dog+water+dispenser PDF link annotation
- https://cdn-cms.f-static.net/uploads/4420030/normal_5fad989777a7c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4393637/normal_5fac551e99d48.pdfIn PDF document text
- https://xuguzopagar.weebly.com/uploads/1/3/4/4/134490213/1013842.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4424647/normal_5fd777930e6fe.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://static1.squarespace.com/static/5fc575d0b8467722f1f2951c/t/5fc90555a19694193ebfb4f1/1607009621354/61936913564.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc6d63eb2e29c7ba9901a48/t/5fd0258cef76c20f2d3e5428/1607476621125/basketball_goal_installation_near_me.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/475472c5-34ca-447c-9612-d4d793834022/zezevoxiwemodisamidil.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/57dd0522-85fd-488a-9ccd-1f4650fd08af/dbt_book_linehan.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4aa8e40c-add5-4e6d-aad5-395f725e1436/kepavexetepozodujafebep.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/db6269ff-5fec-4668-906f-0f0703b1c5c3/gas_law_practice_problems.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc1ae84085bf90c0e029602/t/5fc534329d793648403657c1/1606759474985/rikegabapa.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc5073312facd59cec7706f/t/5fcab1a35113a7255f774254/1607119267382/murder_mystery_party_game_online.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/356b2d76-4a9a-4569-82b6-c3580c7d5a59/xopijibakulisatogu.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cc48.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCC48 | 5268 bytes |
SHA-256: b59f5d32c7d868559033cb9f3d7ed1c9ee92f60056194dec1694ce126fdf3a94 |
|||
font_01_sfnt_off0000de52.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDE52 | 9956 bytes |
SHA-256: 528f06471c2ef8f17169ac92a81fb7456aaf3f513fbf06f4781579763b9259ba |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.