MALICIOUS
194
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a link farm and a redirector to a known malicious URL, indicating an attempt to lead the user to malicious content. The document body, though heavily obfuscated, contains text related to a story book and a URL that matches the malicious redirector, suggesting an advance-fee scam lure. The presence of numerous embedded links, many pointing to Shopify, further supports the link farm heuristic.
Machine Learning
- Nyx PDF Classifier malicious score 0.9931
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/pify?keyword=ramayana+story+book+in+english+pdf
- http://files.foundephemeraart.com/uploads/1/3/0/7/130739740/4038351.pdf
- http://files.mountainandocean.org/uploads/1/3/1/3/131381055/wazebax_solotumobikoz_gelan_zujitimu.pdf
- http://mesefera.hsfhomeconnections-hilton.com/uploads/1/3/1/6/131637309/nofawejomowunu.pdf
- http://files.theahealer.com/uploads/1/3/2/6/132695543/6474107.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://fedorahosted.org/lohit
- http://www.opentle.org
- http://www.daltonmaag.com/
- https://cdn.shopify.com/s/files/1/0437/3803/8423/files/zilivebawegiduroxi.pdf
- https://cdn.shopify.com/s/files/1/0434/1334/0312/files/18461713373.pdf
- https://cdn.shopify.com/s/files/1/0431/7285/5967/files/differential_equations_blanchard_4th_edition.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/50398535586.pdf
- https://cdn.shopify.com/s/files/1/0437/5022/8119/files/what_is_bioterrorism.pdf
- https://cdn.shopify.com/s/files/1/0429/2083/7279/files/benedictine_rule_of_life.pdf
- https://cdn.shopify.com/s/files/1/0433/6559/7342/files/tratamiento_para_caries_dental.pdf
- https://cdn.shopify.com/s/files/1/0433/4462/5822/files/brothers_karamazov_penguin.pdf
- https://cdn.shopify.com/s/files/1/0432/7355/2028/files/mepixid.pdf
- https://cdn.shopify.com/s/files/1/0435/2652/0986/files/77773221227.pdf
- https://cdn.shopify.com/s/files/1/0432/5320/3104/files/11769553439.pdf
- https://cdn.shopify.com/s/files/1/0436/2030/3006/files/75645408831.pdf
- https://cdn.shopify.com/s/files/1/0434/5734/7749/files/93851660309.pdf
- https://cdn.shopify.com/s/files/1/0433/6500/7509/files/xagetekokiwudesezakewaguw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://www.geocities.com/mitra_anirban/hobbies.htmGNU
- http://www.gnu.org/copyleft/gpl.htmRegular
- http://www.gnu.org/licenses/lgpl.htmlRegularDanhHong
- http://www.geocities.com/dnhhng
- http://www.gnu.org/licenses/gpl.html
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00013df2.binda609cd90ce72eb01192bcbb53cdca29dacc99c29e6767041bde1f0915cf1668 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13DF2 | 5556 bytes |
font_01_sfnt_off000150ac.bin601ff2313c148c0d458a5f8f06674ea56627a0d971c5b0cdc135d0396c871027 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x150AC | 2404 bytes |
font_02_sfnt_off00015af1.bineb903a4bcabb0673128613fc2c6a3b3be6b6be0204d11159aa2f590e1d82ee93 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15AF1 | 3740 bytes |
font_03_sfnt_off00016662.binf3e5403e201cb4aabba4862e9d17066d78d8c70691ea1ba4a98ac01fb06a352c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16662 | 4820 bytes |
font_04_sfnt_off000174f8.bineb74435aa33c92ccb841bb7a3a6ac50bdb5358d8b69712c509354d74473a37e4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x174F8 | 2340 bytes |
font_05_sfnt_off00017fc1.bin62a6722e0a7780ce92c38fa958df9f2a9949d21e8884ca563b6443ce5db754b1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x17FC1 | 3912 bytes |
font_06_sfnt_off00018f15.bin6c396c11f6ae740f8937989293ce789070d853422a7f4c875ffa694795473d63 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18F15 | 6992 bytes |
font_07_sfnt_off0001a231.bin9f77b41d25b92864968d64aedadddc2d35d72c4b53ff871cbfd7171df04a48a2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A231 | 12744 bytes |
font_08_sfnt_off0001c9b7.binff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1C9B7 | 4324 bytes |
font_09_sfnt_off0001d7be.bineed323ad3814475636656456199bc6789deed97d9cfd340b4d3d5e82db9b01bb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D7BE | 4548 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.