MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains numerous embedded URLs, with at least one pointing to a suspicious domain ('soxebez.ru') that is likely part of a phishing or malware distribution scheme. The document body, though heavily obfuscated, suggests a lure related to educational worksheets, a common tactic for social engineering.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://soxebez.ru/wix?keyword=free+compound+word+worksheets+for+kindergarten PDF link annotation
- http://lerob.info/87170343242k6d59.pdfIn PDF document text
- http://ruzoboxilotazex.22web.org/what_inferential_statistics_do.pdfIn PDF document text
- http://triple-doska3.club/52256772388h8991.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://d0275d90-c5b4-4c72-b581-d0e2b62fc6dd.filesusr.com/ugd/ee54da_6e844b0ecc144530b784297626cf79a1.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/1ac305e7-e92f-4635-b71d-ff86a5ef815c/how_to_clean_keurig_2.0_k400.pdfIn PDF document text
- https://305aa2e3-e1d2-413d-aa2e-f1bb83d03ded.filesusr.com/ugd/92ee2b_5593f2e2441c49b49541907427926fa6.pdf?index=trueIn PDF document text
- https://uploads.strikinglycdn.com/files/042d92db-ab33-4260-a4c7-0a7ab7c118f3/what_scooters_have_gy6_engines.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/42daa8ee-7554-4a13-8e61-aadd62b48fbf/soboda.pdfIn PDF document text
- https://s3.amazonaws.com/dosipive/how_to_open_the_back_of_a_timex_indiglo_watch.pdfIn PDF document text
- https://cc968bdf-8a18-4a65-a72d-893c706ef441.filesusr.com/ugd/bae363_0cce5bcee3704fa2b8fbfbb729382396.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/jufowokedunod/datak.pdfIn PDF document text
- http://rowodebifofida.rf.gd/altium_designer_viewer_summer_09.pdfIn PDF document text
- https://13fad4bf-7224-44b3-802b-16842e97d241.filesusr.com/ugd/b14664_50d3b4976b1e41079f5d4029204339d2.pdf?index=trueIn PDF document text
- http://tejusadesivuti.epizy.com/mark_carpio_music.pdfIn PDF document text
- http://vaxikiluso.rf.gd/wusoxukimoxuxerubaromutis.pdfIn PDF document text
- http://tesoduv.rf.gd/blood_bowl_2_starting_dwarf_team.pdfIn PDF document text
- http://toxerisana.epizy.com/midabu.pdfIn PDF document text
- https://s3.amazonaws.com/zedilegol/tejuxefebumepazurivoxo.pdfIn PDF document text
- http://piredesoki.epizy.com/fevejibutobujonab.pdfIn PDF document text
- https://s3.amazonaws.com/gebukil/email_marketing_platforms_for_nonprofits.pdfIn PDF document text
- http://zefuxaninegug.epizy.com/apple_developer_center_xcode.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e74be8f4-89cb-4d21-92d3-50a63e3fd3d7/3121908971.pdfIn PDF document text
- http://gimusatis.rf.gd/divul.pdfIn PDF document text
- https://9170d309-caca-4186-8987-bf6b40ce219c.filesusr.com/ugd/baef12_d45505b94fd5409a8cebd567b1b60d24.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cce8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCCE8 | 5648 bytes |
SHA-256: ec5a58772e4191cefbea30a17cecce70b85be9a31f9675d6673d231489049deb |
|||
font_01_sfnt_off0000e00f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE00F | 9712 bytes |
SHA-256: c8c407a3d1f9922b4d56acd5157de4e894573b4d3198b4d4dcca4bfbd605d2bf |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.