MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains numerous embedded URIs pointing to disposable domains, suggesting a link farm or phishing lure. The document body, though heavily obfuscated, contains references to 'wkhtmltopdf', indicating its generation method, and the primary URI points to a site with a keyword related to an 'apologetic essay', likely a deceptive pretext.
Machine Learning
- Nyx PDF Classifier malicious score 0.9994
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jumiwimov.ru/wix?keyword=que+es+un+ensayo+apologetico PDF link annotation
- https://cdn-cms.f-static.net/uploads/4453747/normal_6045bd61bcb5a.pdfIn PDF document text
- https://cdn.sqhk.co/neseleko/iCjfggf/luseligamumil.pdfIn PDF document text
- http://fagumawegoleleb.mypressonline.com/86547647464.pdfIn PDF document text
- https://cdn.sqhk.co/litonesi/hfW7GJC/anatomy_of_the_brain_textbook.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4365660/normal_601f7023e9bd0.pdfIn PDF document text
- http://jifarobajis.sportsontheweb.net/litufiw.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4466679/normal_6010389ac0878.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4466413/normal_605d75b0a6d4a.pdfIn PDF document text
- http://mumolazesinidix.getenjoyment.net/160368212.pdfIn PDF document text
- http://lirifajo.sportsontheweb.net/83151519661.pdfIn PDF document text
- https://cdn.sqhk.co/pasudajuwesa/AQesgj2/47985588977.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/79862e90-ee9e-41d6-9906-e52771be3bf6/69064368747.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/66f0bf7b-9510-4d5e-860d-69d5f147f140/belkin_router_login_password_reset.pdfIn PDF document text
- http://reduxaxu.epizy.com/45656572193.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/43d338ef-3fc8-47a8-ad2c-68d254efaea0/78662322155.pdfIn PDF document text
- http://wupopadena.epizy.com/bibedutefuwifomuwop.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c401193e-07e9-484c-b64a-420b166478b7/70568644784.pdfIn PDF document text
- http://talaxevavilur.rf.gd/bowufesizokobij.pdfIn PDF document text
- http://jimarol.myartsonline.com/algebra_worksheets_grade_5.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d7766618-4bbd-4fa4-b0cf-6c0c05a4b855/the_leftovers_explained_season_1.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8c943495-59eb-4999-8e1d-7bd0011871ec/how_do_you_fix_a_maytag_washer_that_wont_start.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/27935d5b-c85a-48a7-8163-76baf68d5847/weroje.pdfIn PDF document text
- http://merekum.rf.gd/xotonemivudipawuvolojas.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010033.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10033 | 5168 bytes |
SHA-256: b8b768db2032436b1b2aec41b137294821b9b7bf6e48c451e05fc6d48a48b3e1 |
|||
font_01_sfnt_off000111e8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x111E8 | 11644 bytes |
SHA-256: 49b1a1581b5517263660479ad6d4e78ff24980512c1be7b82af8c015b3fc39f0 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.