Malware Insights
The PDF file was identified as malicious by ClamAV and an ML classifier, exhibiting characteristics of a phishing lure and a link farm. It contains numerous external links, with a primary suspicious URL pointing to 'pelibifir.ru'. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external PDF links, suggesting an attempt to distribute malicious content or engage in SEO manipulation. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic suggests a common tactic to bypass security scanners by instructing the user to open a password-protected archive.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/wix?keyword=la+casa+de+los+espiritus
- https://wesuzijuto.weebly.com/uploads/1/3/0/7/130740493/25fdaf18d333fc8.pdf
- https://cdn-cms.f-static.net/uploads/4383149/normal_603683d3917b9.pdf
- https://static.s123-cdn-static.com/uploads/4416140/normal_60099e6b9f518.pdf
- http://kigurumi.org/salvation_army_employment_application_forml5q81.pdf
- https://tibagikusutugox.weebly.com/uploads/1/3/0/7/130775046/3361288.pdf
- https://cdn-cms.f-static.net/uploads/4382793/normal_604a9dda25452.pdf
- https://sekowuwumobof.weebly.com/uploads/1/3/5/3/135394032/lekurazag_vefez_fapowixira.pdf
- https://dofopukirisozut.weebly.com/uploads/1/3/1/4/131437491/b7e936b2.pdf
- http://5coupons.info/is_iphone_4_camera_goods350y.pdf
- https://jilolepileg.weebly.com/uploads/1/3/1/4/131453494/a3c620d.pdf
- https://lisogawe.weebly.com/uploads/1/3/5/3/135312855/sufijinivigari_pudigo_gosodiv_defizisokemif.pdf
- http://circleshtang.xyz/digimon_world_3_training_gym_guidermme2.pdf
- https://bafiredevidif.weebly.com/uploads/1/3/1/3/131384403/22e4db83a1.pdf
- https://cdn-cms.f-static.net/uploads/4472764/normal_602d4c6d92eba.pdf
- http://smartradiobf.ru/dyson_big_ball_animal_vacuum_cleanerhc92e.pdf
- https://jewelilug.weebly.com/uploads/1/3/4/3/134331877/kiwezapikuposo.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/vudivuzakal/59352976933.pdf
- https://s3.amazonaws.com/tadevewuju/the_chess_players_full_movie.pdf
- https://s3.amazonaws.com/gudukupir/gedefevigudaxerovi.pdf
- https://s3.amazonaws.com/lemerisinivum/car_pictures_for_desktop_background_free.pdf
- https://s3.amazonaws.com/fovezewi/what_does_the_long_run_cost_curve_mean.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001225b.bin5f33c7fa41db92d6889486b72218296c3e15de972c97bb18bbff80187af372c2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1225B | 5008 bytes |
font_01_sfnt_off00013371.binf9cb0fe106f80e6fb49dd30d3a9f102ae18b2fdb13b65472b6bd045af0a7bbd2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13371 | 11508 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.