MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for linking to known malicious redirector infrastructure, specifically a URL related to 'discord unbelievaboat servers'. It also exhibits a PDF link farm heuristic, indicating a large number of outbound links. The embedded URLs suggest an attempt to redirect users to potentially malicious content or further phishing lures.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=discord+unbelievaboat+servers
- http://files.aaaction.org/uploads/1/3/2/6/132682974/bcf9a.pdf
- http://files.wrawpg.ca/uploads/1/3/1/4/131453633/surelalerebobu-girubejabegetot-kinopupu.pdf
- http://lefazizi.galaxyelitesecurityproducts.com/uploads/1/3/0/9/130969926/nasagazibetev.pdf
- http://files.caronairbase.com/uploads/1/3/1/3/131380183/1166406.pdf
- http://rajesun.oldetownesalisburymd.com/uploads/1/3/1/6/131606349/7032687.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://353d0541-ba7e-4297-a6a5-50435dbfa421.filesusr.com/ugd/7ab50f_85c83d078be04c6bb36941ea59d3afdb.pdf?index=true
- https://e9eb1b78-1880-42c9-ae3b-f85769d94186.filesusr.com/ugd/f46427_b638f186711e4578bbb353bb54c594d1.pdf?index=true
- https://7368f90d-474d-4464-a8f9-1351d0be4fba.filesusr.com/ugd/c8d394_2ca9da5a10df48d494860355e770aa7f.pdf?index=true
- https://cbbb2af7-fba8-4217-a751-c703f3d607eb.filesusr.com/ugd/26481d_5780972451a14740abe14f9fe2683447.pdf?index=true
- https://72644984-be2d-4aa5-b324-6ca6bbac0c84.filesusr.com/ugd/6bb4a2_d8d8980b441b42908a18640c77fd3b11.pdf?index=true
- https://5e0d2410-5ebf-4d81-b4fd-e56b80c1293b.filesusr.com/ugd/8bf3fc_6f9ece3f8702420abb77b044a3c2a658.pdf?index=true
- https://95f331af-c425-46a9-b450-7d494074bf30.filesusr.com/ugd/185c00_2780aab4a2134082a8403ce33bdd46e2.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000592b.bin52305bb97d8784530686a3bfac0ba3bd9f1601544d65b56ae3ea6213efa29d50 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x592B | 5132 bytes |
font_01_sfnt_off00006aac.bin6f2ff8fd1675410e0bcdba0112db8db9fc8986a1f1f2a251fdbf37d0929289b5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6AAC | 3812 bytes |
font_02_sfnt_off000079d9.bin16b788d91a042c67f23c2b9ed239c68d4342570b4234112f216ac06278b9f978 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x79D9 | 10840 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.