MALICIOUS
196
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was flagged by multiple heuristics, including a machine learning classifier and ClamAV, indicating malicious intent. It contains a large number of external links, suggesting it is part of a link farm designed to direct users to potentially malicious content or phishing sites. The presence of a 'Password-protected archive handoff' heuristic indicates a common tactic to bypass security scanners by encrypting a payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zajinet.ru/wix?keyword=artemis+fowl+the+seventh+dwarf+pdf+weebly
- https://cdn-cms.f-static.net/uploads/4368742/normal_6051ed9e6acf7.pdf
- https://cdn-cms.f-static.net/uploads/4489414/normal_60443016b9c58.pdf
- https://cdn-cms.f-static.net/uploads/4485930/normal_5fd7a0fbcdd9b.pdf
- https://static.s123-cdn-static.com/uploads/4456685/normal_5ff5855ddce79.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://288c7b4b-0494-48f6-8ee2-9dd519b96b0a.filesusr.com/ugd/a107db_836754842f324cbf891d45eecbe3eb16.pdf?index=true
- https://0315d410-4255-45a3-9477-873949dd02ac.filesusr.com/ugd/f85006_cfead1df49ef43d4a733394b5b6807af.pdf?index=true
- https://32e47638-7206-44c1-ad53-5c6f9176402e.filesusr.com/ugd/e00742_3930fa74a3f04bb0b1a1c956f5cbe3af.pdf?index=true
- https://3794eb9c-cc8b-492c-aecc-44533f76aaa6.filesusr.com/ugd/1ee69b_57f87eeb6eb2400b821b98e5e42608b1.pdf?index=true
- https://8d90b851-447f-4cfc-ac95-1e867b71b983.filesusr.com/ugd/b371d9_9cb53dd2730a4fa991c2c6720fbed029.pdf?index=true
- https://1f49b3f1-4b09-4f89-88df-03804352fc9a.filesusr.com/ugd/a51aec_3425bca2fc2643cbb71f2648aab94b51.pdf?index=true
- https://3df06c22-1e8a-4082-8cc2-a0fdc0609706.filesusr.com/ugd/d86e81_feaffd405a75472ea99c1b2a61bb4a4d.pdf?index=true
- https://0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com/ugd/8b97dd_4fe1d145afdb4b2798d8d79cbbaa44a3.pdf?index=true
- https://2df7536a-ab64-4dd3-a6ca-98e0eca144a4.filesusr.com/ugd/de578f_eaab0f14c9464a3c91fc51fe3445729f.pdf?index=true
- https://a2876ee3-c470-454a-91e2-e108d831033a.filesusr.com/ugd/e8dba5_b776d47102b9419eb60d63aeee8dc3b4.pdf?index=true
- https://a49aa754-465e-4bbd-924e-b3d0e7b66bd4.filesusr.com/ugd/81d6a4_671e350ade644c539a4a62f8ed97fa91.pdf?index=true
- https://36fc1fe3-b646-4cc1-b6e9-de51469aea27.filesusr.com/ugd/3eb4bd_e41017b5d1b5425a996f3ec347fc9321.pdf?index=true
- https://s3.amazonaws.com/xufaxoferugod/48528720958.pdf
- https://e0ff2378-281a-4ea3-95ae-419c526fdc99.filesusr.com/ugd/0baf77_5f43d9a25b564698b7287aa76d154617.pdf?index=true
- https://s3.amazonaws.com/lizuseguwix/awara_bengali_full_movie_hd_720p.pdf
- https://5a1138df-423b-4a5d-a7c7-36223740754e.filesusr.com/ugd/a72fa8_452379aa510a4d559617bc75d069382e.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f3f6.bin2dc3bea98417a72b0d8aa25765eb00f2c105aa052701bbacc31e39bcdd168dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF3F6 | 5664 bytes |
font_01_sfnt_off0001071e.bin4eb496ccaddc95c598e3b3271b68de70595227b05b4cb34d77cecf156ddd76a6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1071E | 11124 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.