MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/wix?keyword=enchantment+guide+hypixel+skyblock'. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to trick the user into visiting a potentially harmful site. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=enchantment+guide+hypixel+skyblock
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://static.usrfiles.com/ugd/48d9a1_9cf05a411501447ba41f0baea4d975c8.pdf
- https://static.usrfiles.com/ugd/b8c837_c7e2ac6b38044181aedb1d95bd66ee17.pdf
- https://static.usrfiles.com/ugd/9dda13_57a5876cee26490aa36928b1363ca041.pdf
- https://cdn.shopify.com/s/files/1/0432/0559/1200/files/965223726.pdf
- https://static.usrfiles.com/ugd/6116da_682167b5016b494e8fc5c1fd7dc95019.pdf
- https://static.usrfiles.com/ugd/3ce946_f924461deb48481c84d9e03b8128a1b3.pdf
- https://cdn.shopify.com/s/files/1/0431/8255/5300/files/apple_app_store_logo_guidelines.pdf
- https://cdn.shopify.com/s/files/1/0437/8735/4270/files/xiduwegodimukedolelan.pdf
- https://cdn.shopify.com/s/files/1/0464/7718/1080/files/xizefepibovaxajivusuvot.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000865b.binfe0a971cf7c3bc646efabcab0a0508f33e5206d7361d273db16a9f7df04ae0e6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x865B | 5720 bytes |
font_01_sfnt_off000099b3.bin8d852a1b3cdbca3c03c6c4c624a2ad6f027a22018b993d65f57a07634ec6eed4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x99B3 | 14212 bytes |
font_02_sfnt_off0000c5e5.bindc743b41e5c9b9e4d56ad8c22d1311c6eb3cecbc0d04401a7a33aeed2fa7944a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC5E5 | 16244 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.