MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous embedded links, with one specifically pointing to a known malicious redirector infrastructure. The document body, though partially corrupted, contains text that appears to be a lure related to 'pba 2k14 apk' and includes the malicious URL. The presence of a link farm and the ML classifier's high confidence score further support the malicious nature of this document.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=pba+2k14+apk
- http://zavoponok.linwoodfire.com/uploads/1/3/0/8/130873782/bimisevekujumasaneto.pdf
- http://xapeve.marissaoneil.com/uploads/1/3/1/4/131438562/4902397.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cdn.shopify.com/s/files/1/0437/2958/4282/files/california_child_support_calculator_user_guide.pdf
- https://cdn.shopify.com/s/files/1/0429/3161/7945/files/interface_contract_document_template.pdf
- https://cdn.shopify.com/s/files/1/0431/5981/4306/files/pl_sql_interview_questions_and_answers_for_3_experience.pdf
- https://cdn.shopify.com/s/files/1/0432/3724/5085/files/hyperbole_and_a_half.pdf
- https://cdn.shopify.com/s/files/1/0437/4760/6679/files/22839807651.pdf
- https://0b4d7da4-9710-4552-abe8-61d790163cbc.filesusr.com/ugd/96564c_d75108c9323e4b09949c7c7f2f745f5d.pdf?index=true
- https://34f7060d-3ab7-457d-8d2b-0c5aa3c0775d.filesusr.com/ugd/d8966e_b7641a46b1b1474b9e65a4ca3c6acdfa.pdf?index=true
- https://c23404da-0451-4b7f-80e6-a1a8e139e0cd.filesusr.com/ugd/ea9bdf_a335805a2d684b54bd418b730ab5dedb.pdf?index=true
- https://f9b81543-79bd-4868-8952-af14d78960d2.filesusr.com/ugd/b926a8_e3d504e95f904b3fb1159c0a9e1a69b7.pdf?index=true
- https://c61b34b9-558d-416d-8d3a-de9cc65e25c0.filesusr.com/ugd/bf0735_21291315200a4ee097903de360ff9074.pdf?index=true
- https://9de8ad10-836d-4523-ade9-18d1975f29d6.filesusr.com/ugd/c8683e_ea0af676621e4bf891cc249a5d4a42af.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004c89.bin7c7dcfede1a0719055366569748797cbe6fff760dcb8d6872f48967b8e71edfb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4C89 | 4984 bytes |
font_01_sfnt_off00005d9f.binc0d8919fb69a09be7347b5c8231b838efc88a5c094abe14206bcc49e6e2ce610 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5D9F | 10080 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.