MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous external links, including one to 'maypoin.ru' which is presented as a 'stable program 6th edition pretest answer key'. This URL, along with others pointing to link farms like 'cdn.sqhk.co', suggests a phishing or malware distribution scheme. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or trojan delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/wix?keyword=stable+program+6th+edition+pretest+answer+key
- https://cdn.sqhk.co/jigugabopu/hfGgd0J/simaridajumamologoja.pdf
- https://cdn-cms.f-static.net/uploads/4378378/normal_600b75279dc6d.pdf
- https://static.s123-cdn-static.com/uploads/4393190/normal_5ff0dcb2e6091.pdf
- https://cdn-cms.f-static.net/uploads/4403537/normal_6019761d0504a.pdf
- https://cdn-cms.f-static.net/uploads/4409826/normal_6014aae5ddc02.pdf
- https://cdn.sqhk.co/dozirolizilu/FT7vPjc/91996660005.pdf
- https://static.s123-cdn-static.com/uploads/4379048/normal_5ff8b59b79953.pdf
- https://static.s123-cdn-static.com/uploads/4408873/normal_5ff4f98a8ccdf.pdf
- https://cdn.sqhk.co/nutakurij/QjgLElc/modiruza.pdf
- https://cdn-cms.f-static.net/uploads/4453890/normal_604d659f19323.pdf
- https://cdn.sqhk.co/finizaga/xQcQHij/old_songs_ringtone_for_android.pdf
- https://cdn-cms.f-static.net/uploads/4418778/normal_6010fa29d0806.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://53f03ce6-db0b-4f41-9bfc-6956ba41e1f4.filesusr.com/ugd/727e0f_b09ae47b11f541e38cae390df641cf9c.pdf?index=true
- https://s3.amazonaws.com/lejivugeleguwod/fab_cheque_book_request_form.pdf
- http://zewogukanonudut.epizy.com/55005946401.pdf
- http://ginojakoli.rf.gd/talerepizulogovapipovakos.pdf
- http://fudotebu.epizy.com/74793769465.pdf
- https://1a899ca6-11bf-4464-971e-4bf0b885e765.filesusr.com/ugd/4ac3ff_f594d42593aa4b969b53849c2b76a35d.pdf?index=true
- https://86cafecd-0af7-43e6-b578-14605c742a6c.filesusr.com/ugd/c4ddd0_c59b453268f845a8a532c4dddf74e07d.pdf?index=true
- https://s3.amazonaws.com/panokojol/storyboard_making_software_free.pdf
- http://kexeban.rf.gd/archeologia_romana.pdf
- https://04a9e765-cf69-4035-9b9a-998d8fb4e692.filesusr.com/ugd/8c5016_7f6c0cb43535439aa8551f53569f2b43.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ebde.bin176024213bc86baab4258c26ae285611a5c822172c94273d0f208075a5101f16 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEBDE | 5816 bytes |
font_01_sfnt_off0000ff88.bind5225375b86ffcc679a51956a634deb14b78e7a2e5ec6744abbd0947428f0f96 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFF88 | 10892 bytes |
font_02_sfnt_off0001249f.bina542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1249F | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.