MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=la+boite+a+merveille+r%25C3%25A9sum%25C3%25A9+pdf'. Additionally, another heuristic indicates a PDF link farm with numerous external links, suggesting an attempt to distribute content or lure users. The ML classifier also strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=la+boite+a+merveille+r%25C3%25A9sum%25C3%25A9+pdf
- http://fontawesome.iohttp://fontawesome.io/license/
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cdn.shopify.com/s/files/1/0431/4379/0760/files/1994_ford_explorer_owners_manual.pdf
- https://cdn.shopify.com/s/files/1/0435/9494/0575/files/66839390519.pdf
- https://cdn.shopify.com/s/files/1/0431/8704/4510/files/lananefuzutuvo.pdf
- https://cdn.shopify.com/s/files/1/0438/5875/5749/files/ethiopian_airlines_crash_report_2020.pdf
- https://static.usrfiles.com/ugd/930050_3aeee2a4cf414bdfa3f5210cff74f3c6.pdf
- https://static.usrfiles.com/ugd/b8c837_f9af000aa86d462abb3dd7bdb27041ae.pdf
- https://static.usrfiles.com/ugd/cec570_3555d888e1514d3e834c89c6f3609d7d.pdf
- https://static.usrfiles.com/ugd/63d3ad_52d7edf4d89c46c6b96543912f34e839.pdf
- https://static.usrfiles.com/ugd/07625c_7f12a0528c6b41f5b1e421b38768230a.pdf
- https://static.usrfiles.com/ugd/0f5b72_5010526021c14a84b1a32ac5e34ccc9e.pdf
- https://static.usrfiles.com/ugd/0286dd_6c03f9619a224a50a5a8bb72d58bc33e.pdf
- https://static.usrfiles.com/ugd/b8c837_eb8056e2478d4a9590e3d1a63ee3de1e.pdf
- https://static.usrfiles.com/ugd/b8c837_56651e16c1894a7dbea5127926c6d992.pdf
- https://static.usrfiles.com/ugd/a2e20a_8b2c5542bf0a41faa0707ba6d5610544.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007968.binbd166d64c4ac8954e2933e6e483f73d556bfd5753cccffed8791ed292fde615a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7968 | 1660 bytes |
font_01_sfnt_off000081aa.bin7d5633911d09556f64fcc323deb37e02bd1aefa5930169a1597aeb3ea51680bd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x81AA | 5468 bytes |
font_02_sfnt_off000093ef.bina89c69c98f1cd24a8224a1e960de6e598c5b4d0e694538b6fd4074aca50238e2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x93EF | 12196 bytes |
font_03_sfnt_off0000ba76.bin1957429f870e3021b6bba02e9571c572e3efb2afeeaf289904279bda08619914 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBA76 | 16060 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.