MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document contains a link to a known malicious redirector, disguised with a seemingly innocuous keyword. The PDF also hosts a large number of external links, suggesting it's part of a link farm designed to manipulate search engine results or distribute malicious content. The ML classifier strongly indicates maliciousness, and the embedded URL is the primary indicator of compromise.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/123?keyword=one+direction+meet+and+greet+experience In PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/83c8b921-bcf0-4253-afff-5300d33fdba9/gusesonozodonikadeji.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0499/9230/2752/files/simplest_form_worksheets_6th_grade.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0440/6929/0149/files/54653963725.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0481/7669/3397/files/epub_to_converter_portable_download.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ec514b4c-6af6-4426-a2a1-27a895b72e76/27031888561.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6f4fdc1a-c630-46e9-b3c7-749a4cacf22f/55945018890.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0483/4328/5923/files/84637698715.pdfIn PDF document text
- https://s3.amazonaws.com/lanorolowu/mapa_fisico_de_africa_para_imprimir.pdfIn PDF document text
- https://s3.amazonaws.com/bokexizometun/always_remember_us_this_way_piano.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1ecb361a-988f-46ca-b811-151b4841150c/noreen_renier_books.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0501/3120/6301/files/android_build.gradle_implementation_vs_compile.pdfIn PDF document text
- https://s3.amazonaws.com/jamokaroxoj/18376320279.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/aaccb143-412a-4ab2-a776-8302eafd833f/nirumavimirimij.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e68adca8-fc62-4222-be71-226c162401f6/god_has_a_plan_for_your_life_the_discovery_that_makes_all_the_difference.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ca2dda30-3961-4ca0-9c07-3586e013c086/britannica_encyclopedia_android_apk.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0432/5418/6146/files/aprendizaje_visual_definicion.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2d2e052a-1cb7-4083-a8cd-e27c58200819/fnaf_at_the_krusty_krab.pdfIn PDF document text
- https://s3.amazonaws.com/kitakilesa/20828495357.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0486/4979/7790/files/nissan_forklift_mcp1f2a25lv_parts_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e7084e33-f810-449a-8983-6b3395930b92/cajones_de_cimentacion_definicion.pdfIn PDF document text
- https://s3.amazonaws.com/zirojopemup/38794446611.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6007b06d-0186-4c19-b2b8-fde80200cd33/56687087664.pdfIn PDF document text
- https://s3.amazonaws.com/nonabafat/network_security_tools.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006f3e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6F3E | 5280 bytes |
SHA-256: 7f14e1d06282187bf7a35147d143cbe7ff0c65ee3f361c90f185044c52449175 |
|||
font_01_sfnt_off0000811b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x811B | 10876 bytes |
SHA-256: b3d10c2ff5be191cc6944c86d8b534922550cf2ce2a0967dad5e9f7976d93a62 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.