MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains numerous links, including one pointing to a known malicious redirector at 'ttraff.com'. The document body, though malformed, suggests a lure related to a 'Bible study book of James pdf'. The presence of a link farm and a malicious redirector indicates an attempt to drive traffic to malicious infrastructure, likely for further exploitation or phishing.
Machine Learning
- Nyx PDF Classifier malicious score 0.9975
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/pify?keyword=bible+study+book+of+james+pdf
- http://tolaputap.hopeconnexion.org/uploads/1/3/1/6/131637136/rikujofag-saxixaluta.pdf
- http://files.insights4less.com/uploads/1/3/1/4/131407102/begabutirobuzi.pdf
- http://xisoripe.mrschaeffer.com/uploads/1/3/2/7/132740873/dab64994b015a.pdf
- https://cdn.shopify.com/s/files/1/0433/4842/6902/files/jafasolosunufimixaxa.pdf
- https://cdn.shopify.com/s/files/1/0434/3349/2641/files/zusogepubetotetudopafota.pdf
- https://cdn.shopify.com/s/files/1/0435/2881/4746/files/83792507132.pdf
- https://cdn.shopify.com/s/files/1/0427/8275/2935/files/50020745708.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tizerosotusalasebix.pdf
- https://cdn.shopify.com/s/files/1/0429/1382/4927/files/nusupuvilewoseso.pdf
- https://cdn.shopify.com/s/files/1/0428/8462/8633/files/502741950.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xanixiki.pdf
- https://cdn.shopify.com/s/files/1/0437/5488/1185/files/ainslie_macleod_the_instruction.pdf
- https://cdn.shopify.com/s/files/1/0434/6858/7174/files/geography_alive_textbook.pdf
- https://cdn.shopify.com/s/files/1/0434/0508/2780/files/kizebisibal.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 10
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000658a.bin7538a7b801b14375a364d9459c13a2bba067566dfe6ced97c31fefc7ddf56719 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x658A | 5520 bytes |
font_01_sfnt_off00007845.bin1620336da6018abf771a3b64a4739dbc5cc5761e5bcfd31f9568e9163b5e6178 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7845 | 2656 bytes |
font_02_sfnt_off0000834a.bin778061bc12a3e7806d52a1624391743f2e703f8cd6887dddafb994fe6bb204ba |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x834A | 5560 bytes |
font_03_sfnt_off0000950a.bine23308bb06bff427f4fe2d795198e016b2e9db23d45fd702446b15ef1a1323d1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x950A | 3048 bytes |
font_04_sfnt_off0000a116.bin6d897259d7ab9db79b0dbb16904cd99ff486aa7f4a475590a5d3e44eab6e0eed |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA116 | 2328 bytes |
font_05_sfnt_off0000abce.bind4cda5a9ecb2558448f754249352cd4d73a8f7efff03060ee9a54ebf713292d1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xABCE | 2604 bytes |
font_06_sfnt_off0000b6e4.binb3976ad28991401f3a7e0d936621f3963ed8fd81aff5bedc9e25cf6548b1959b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB6E4 | 2108 bytes |
font_07_sfnt_off0000c0ba.bin6a627f92c2f4bcb82db7d9368088baf3d752b8ed470710abeb431d497dfe9428 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC0BA | 14608 bytes |
font_08_sfnt_off0000ee0c.binb4bd494035f53cc808e33b429063b31ae12b55b4bee792b64b083130b128eebc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEE0C | 16944 bytes |
font_09_sfnt_off00010675.bind404f64416bf1ff5ad76d6d0ab30c7620aa9735638cfece5436aad8d6ad80edc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10675 | 2608 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.