MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains numerous external links, a technique commonly used in phishing or to distribute further malware. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of generated links, suggesting an attempt to manipulate search engine results or distribute malicious content through a link farm. The ML classifier and ClamAV detection strongly indicate malicious intent, likely related to phishing or malware delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9990
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://kuzutuzo.ru/wix?keyword=stained+glass+transformations+worksheet
- https://cdn.sqhk.co/xataruzepape/b4gg8m5/6852658222.pdf
- https://cdn.sqhk.co/ravusigi/ijWjgva/84671417777.pdf
- https://cdn.sqhk.co/winudesuw/cihhagj/cookieswirlc_videos_roblox_piggy.pdf
- https://ripafikumitepi.weebly.com/uploads/1/3/4/6/134622323/suruwebejidur.pdf
- https://wufonujixu.weebly.com/uploads/1/3/4/3/134386315/45573cb9ec7.pdf
- https://fakivafepupu.weebly.com/uploads/1/3/0/8/130873921/3800089.pdf
- https://cdn.sqhk.co/xopuxuvop/hcs2rjb/roblox_promo_codes_generator.pdf
- https://cdn.sqhk.co/jalizovi/gdphcgg/super_bee_drag_car.pdf
- https://roturusuwanowus.weebly.com/uploads/1/3/4/3/134363773/nadarexomov.pdf
- https://lepebixetuvenal.weebly.com/uploads/1/3/4/6/134634058/42c857.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://d5fd0048-bb8d-45a1-ba21-28d1cb0b7162.filesusr.com/ugd/5e8de6_b376a8fdda6d429b9c6cffb63e5a14d9.pdf?index=true
- http://sugunava.epizy.com/firing_squad_battleground_game.pdf
- http://jejelofekek.rf.gd/77049582756.pdf
- https://52a1af19-6946-4c37-aba6-ab00a30e4874.filesusr.com/ugd/5dc3ca_1734569fcbf046debfbeac1feaf0c29c.pdf?index=true
- https://77483064-5892-4b52-b419-66e751946b77.filesusr.com/ugd/ef7b09_5a5fb1624d42455e90cc33c4d1d11836.pdf?index=true
- http://dukidejulorib.epizy.com/biodata_hd.pdf
- https://a581e706-3bf6-41fb-8978-ad4d4077590d.filesusr.com/ugd/afbe6b_3783c02b48184166a269f7a1da9271e4.pdf?index=true
- https://8ab1a2d5-e5b1-44c5-a28c-e09959565f0d.filesusr.com/ugd/eb712c_d426a416f6294ba0b788536af37e6ef3.pdf?index=true
- https://5efcf519-4c71-4be9-a00f-e1d47ba804c5.filesusr.com/ugd/ebcc4b_849c062d70c543ff95a1a050e92ccc4f.pdf?index=true
- https://9e084d23-5bbf-42ad-98e9-fa9200f8584e.filesusr.com/ugd/4f663b_b9822d35db48440892a9a41527d599ff.pdf?index=true
- https://8c4778c4-ed17-4cf1-86f9-5448e21c5c15.filesusr.com/ugd/6da380_746126dbbf154b8fb01bd56516c17490.pdf?index=true
- https://5be7aec3-7d66-433b-ae1d-2bfb807ddf2a.filesusr.com/ugd/24deb6_32ebfd79a43b443c96d9421716c127c0.pdf?index=true
- https://5c9c3928-af7d-4195-9e43-9647d7263c15.filesusr.com/ugd/508998_75a6bb3c5cdc429da060f9913ca2c3ae.pdf?index=true
- https://858e1da1-ad31-4e5b-aec0-89c59c6c71f6.filesusr.com/ugd/6240f8_37cf3b7ae38e483d9cafc1227ccdf59e.pdf?index=true
- https://d1897088-ef6e-4b60-8303-910b4b551fc1.filesusr.com/ugd/4cfbbd_e5a0e70435c54250a6f9a6df6c042f7f.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f392.bina4a9fb4bcbe4ba412e6e86b24edec92d2e9b67538d434e4d9c532ddfa72f2f76 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF392 | 5580 bytes |
font_01_sfnt_off0001066e.bin7eef1f607a480d561656163d025a45dbb8ce0eabc335a8256896e26916672887 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1066E | 10288 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.