MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://traffmen.ru/123?keyword=declares+laws+unconstitutional+what+branch'. This URL is likely used to lead the user to a malicious site. The PDF also contains a large number of external links, indicating a link farm, and is flagged by an ML classifier as malicious. No scripts were extracted, but the presence of a malicious redirector URL strongly suggests a phishing or redirection attack.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffmen.ru/123?keyword=declares+laws+unconstitutional+what+branch In PDF document text
- https://jomupalekiloja.weebly.com/uploads/1/3/4/3/134310494/gagiguna_ketomupibu_potopotobex_dusateravebidi.pdfIn PDF document text
- https://digafixi.weebly.com/uploads/1/3/0/7/130776371/1887816.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366384/normal_5f879af6529f5.pdfIn PDF document text
- https://wojeribexojuxu.weebly.com/uploads/1/3/1/8/131856158/bagurigovig_nufewufapupimu.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://konibuxeru.files.wordpress.com/2020/11/56429619414.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5aefbfe9-0fe9-40d0-8484-fea4f749e1ff/81734435277.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7f676ccf-88af-4c92-8f0f-fab9586d172d/vulesebubukavew.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9ba0f329-6c22-451e-a32a-df55840ac6a0/32817096428.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0e99a3b6-4e20-4a4a-8cb5-8d04c7677e3c/39144050321.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4a05df84-5798-476b-affb-a3e2507158a1/strawberry_shortcake_collectors_pric.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/306003ae-cab0-4b34-99f8-052e15523931/destiny_2_militia_s_birthright_god_roll.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a2695d1d-3597-4be3-bf13-79e914ee360e/questes_de_prova_de_arte_sobre_foto.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/afaa76b9-ca7b-428d-b648-06521fc03558/labujotuxagex.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010785.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10785 | 5120 bytes |
SHA-256: 4f68c9901e1b4ee612734de6a9d441911c887ccf71fc543c17762e0e1866a1c9 |
|||
font_01_sfnt_off00011900.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11900 | 10904 bytes |
SHA-256: b71aafd3e66cc524c4808f86fa8e2b9b90e60bf93794281343baa5fe07d6fb1a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.