MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains numerous external URIs, many hosted on disposable domains, suggesting a link farm or phishing lure. The ML classifier and ClamAV detection strongly indicate malicious intent. The presence of embedded URLs and the document's deceptive content point towards a phishing or malware distribution campaign, likely initiated via spearphishing.
Machine Learning
- Nyx PDF Classifier malicious score 0.9991
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/wix?keyword=solutions+cloze+worksheet+answers
- https://finowizefi.weebly.com/uploads/1/3/1/3/131383614/momed.pdf
- http://pazefezos.mywebcommunity.org/iso_ts_16949_standard_free_download.pdf
- http://movawizaxaxato.mywebcommunity.org/16420231729.pdf
- https://nogorixarolixi.weebly.com/uploads/1/3/0/7/130740589/393f9aa0f7b9.pdf
- http://rafupofamurawaf.mygamesonline.org/schwinn_ic3_console_commands.pdf
- http://introdom.ru/android_xml_bitmap_sizeckt9a.pdf
- http://woxijakuzadajew.getenjoyment.net/35905226029.pdf
- http://silkhfig.bid/casio_g_shock_mrg_g1000_price_in_indiavoe3i.pdf
- https://cdn.sqhk.co/zifeduwa/jbUMzWk/basketball_games_online_unblocked_at_school.pdf
- https://werirubiteda.weebly.com/uploads/1/3/5/9/135972418/josazimunuseg-xewaredez.pdf
- http://zoluwofemofuper.sportsontheweb.net/2010_camaro_for_sale_jacksonville_fl.pdf
- http://fovajifep.iblogger.org/89559529768.pdf
- https://cdn.sqhk.co/luwibajik/VvChhhc/30160085167.pdf
- http://ludshop.xyz/57645527022suy6x.pdf
- https://nobaletakalesig.weebly.com/uploads/1/3/2/3/132302751/443e3435f5615.pdf
- http://bejawutipage.mywebcommunity.org/93398705175.pdf
- https://dibozuvoba.weebly.com/uploads/1/3/4/6/134692955/d6179c954c.pdf
- http://7gusevshop.website/vejebugufesofikukuri3t0xv.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://vilepobafomunow.atwebpages.com/char_broil_infrared_grill_ribs_recipe.pdf
- http://dovanokeji.epizy.com/segatitimoragemenital.pdf
- http://kifugelewepin.epizy.com/compartment_exam_date_sheet_2019_class_12.pdf
- http://xotaferuju.myartsonline.com/83394780232.pdf
- http://rixuzomobe.epizy.com/geekbench_4_pro_apk_latest.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00015399.binb7f317aa0f29cd34df008dc84d8f376d2685882a57a4a5cd0d86477d0adf885a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15399 | 2828 bytes |
font_01_sfnt_off00015d94.binc0604237c2e55f9eb6683b470e112cca85b0e23278c3ee008912e1f9e0104f7b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15D94 | 5196 bytes |
font_02_sfnt_off00016f55.bin7c3758ef495ef6ee77ebe71281188190bd67342450715a941e2bceb92aad31fb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16F55 | 10188 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.