MALICIOUS
162
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file contains numerous links, with one identified as a malicious redirector. The document body, though heavily obfuscated, contains a URL that matches the malicious redirector. The ML classifier strongly flagged this PDF as malicious, and the presence of a link farm suggests an attempt to distribute malicious content or engage in SEO manipulation for malicious purposes. The primary IOC is the identified malicious redirector URL.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=android+17+and+18+tournament+of+power
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://static.usrfiles.com/ugd/15ebe2_31eb0c1934fe43a78efd144961b63fb4.pdf
- https://static.usrfiles.com/ugd/b8c837_9624d14830c74476a1917027b3de8b7f.pdf
- https://static.usrfiles.com/ugd/2486b5_85648b6cdcac4609956d64b38860435d.pdf
- https://static.usrfiles.com/ugd/432b07_f338fc16e3fe4fc7abd085e15dae671c.pdf
- https://static.usrfiles.com/ugd/4b7290_124f5a326c544d71857b430cfb8d8a37.pdf
- https://static.usrfiles.com/ugd/1ee69b_747525a3bd6e409d94470eaba0a78a3e.pdf
- https://static.usrfiles.com/ugd/0adedf_4861b821c6874f6dbcdc3b7379b86cb4.pdf
- https://static.usrfiles.com/ugd/756799_db675891516a4684ad9a33341eabd04f.pdf
- https://static.usrfiles.com/ugd/111c46_c2e572db09fb4e8ca41616cb72b8271f.pdf
- https://static.usrfiles.com/ugd/822ecd_2b9b0f61a892486f94646926d14d7cca.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/35209966956.pdf
- https://cdn.shopify.com/s/files/1/0431/2439/2087/files/fitodu.pdf
- https://cdn.shopify.com/s/files/1/0433/9925/0072/files/kubijubutepuxexozamaj.pdf
- https://cdn.shopify.com/s/files/1/0438/8470/7992/files/advanced_editor.pdf
- https://cdn.shopify.com/s/files/1/0433/7251/1386/files/6_claves_para_aprender_ingls_gratis.pdf
- https://cdn.shopify.com/s/files/1/0454/7185/8838/files/apologeticum_tertulliano.pdf
- https://cdn.shopify.com/s/files/1/0440/6041/0006/files/50238491496.pdf
- https://cdn.shopify.com/s/files/1/0428/9721/1558/files/sinonimo_de_conforme_exposto.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001b2bc.binc49b80f2b67c4fd49bf48f000af19ea3482fe734367b8f5820b0a5c24d0b0caf |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1B2BC | 5664 bytes |
font_01_sfnt_off0001c652.bin7baff6ba42d04140423584a8dfceb631ac2d878975bf7787917d6109407e2b88 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1C652 | 5384 bytes |
font_02_sfnt_off0001d8ad.bin28272d34785d5ce1c9b98223e6fd79c8d70d03725782464c46893bb9f5c88c07 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D8AD | 10816 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.