MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
T1204.002 Malicious Link
The PDF contains a malicious redirector link disguised as a computer manual, aiming to lure users to a harmful site. The ML classifier strongly indicates malicious intent, and the presence of a link farm further supports a malicious distribution strategy. No scripts were extracted, but the primary attack vector is the embedded malicious URL.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=hp+envy+23+touchsmart+all-in-one+manual
- http://jurunibu.drbelindaketel.com/uploads/1/3/1/8/131857204/d0e1dad8bf7a.pdf
- http://fizuzepiz.partainsenglishclass.com/uploads/1/3/0/7/130775732/4686999.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cdn.shopify.com/s/files/1/0434/6609/6806/files/toneje.pdf
- https://cdn.shopify.com/s/files/1/0434/2782/3765/files/93178463062.pdf
- https://cdn.shopify.com/s/files/1/0434/8172/7129/files/luwifarilo.pdf
- https://62ef9ce6-6eb9-42c4-a64c-1b4686e905f6.filesusr.com/ugd/44b221_494eb6c874dc4d73b14d4294bade6a73.pdf?index=true
- https://4ab5c431-c835-4b68-b0bb-d0ac3a6c89b2.filesusr.com/ugd/80685d_4d469d1913704360b70d15637ba40c6f.pdf?index=true
- https://a12c9e18-5ebc-4c96-a0fa-e1e390a727b5.filesusr.com/ugd/4c1554_1b8527b120324113a3d7abf8173b6ce0.pdf?index=true
- https://1c373c56-23b9-4e0b-b782-18577ce72556.filesusr.com/ugd/10cedf_fa87e109b0724935a89d285b17833dc3.pdf?index=true
- https://56b0b35e-8343-40d6-9e7a-a67c13fbee78.filesusr.com/ugd/162fe6_49688e7f00774c55a086c226be60aedb.pdf?index=true
- https://47608300-8590-46b4-9fe4-1dc8e3843566.filesusr.com/ugd/9d869b_332dec52176c4e09a31fbd07ca505b4d.pdf?index=true
- https://28898e51-8a86-4441-9d9b-ee589b508c92.filesusr.com/ugd/accd1f_4ee12567d0b0482b8eb88d80bd9ac12c.pdf?index=true
- https://3b15e27d-00c6-4204-a79d-64edbb362349.filesusr.com/ugd/5438e3_06a496e9923740c3a1c96b709f88a80d.pdf?index=true
- https://94d97d3b-102f-4971-82ec-95c034af60c2.filesusr.com/ugd/d9d1f5_2de1cc1dfa444a1cb2910ff2e3764280.pdf?index=true
- https://bb4f8a40-0594-4692-ac97-894b705c5ab9.filesusr.com/ugd/edb4a7_4b4fe9d8702c4e1881095e1d940c5f92.pdf?index=true
- http://www.hp.com/go/contactHP
- http://welcome.hp.com/country/
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005cc6.bincec02c9d4993804c1d3a6a02a96732e3f0c924227bfc4d0350e549a484497a19 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5CC6 | 5624 bytes |
font_01_sfnt_off00006fcf.binb700208a9a3595f8cf172dec76fe839f1abb88e0c3f4f31d4d8497c71f4c0304 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6FCF | 10660 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.