MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a link to a known malicious redirector infrastructure, identified by the 'PDF_MALICIOUS_REDIRECTOR_LINK' heuristic. The ML classifier also strongly flagged this PDF as malicious. The embedded URL 'https://traffine.ru/strik?keyword=list+of+kirby+enemies' is the primary indicator of malicious intent, suggesting a phishing or malware delivery attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9929
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffine.ru/strik?keyword=list+of+kirby+enemies In PDF document text
- https://jeretidaker.weebly.com/uploads/1/3/4/5/134595905/jowibagulo.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4371508/normal_5f8f3b369748f.pdfIn PDF document text
- https://zejuwotozago.weebly.com/uploads/1/3/4/6/134647352/5483633.pdfIn PDF document text
- https://welavofewefose.weebly.com/uploads/1/3/0/8/130813025/5069808.pdfIn PDF document text
- https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/9460805.pdfIn PDF document text
- https://wixurawitubeza.weebly.com/uploads/1/3/4/3/134319602/xubevidomitani.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4386074/normal_5f93b0ca96c94.pdfIn PDF document text
- https://guzifako.weebly.com/uploads/1/3/4/0/134096492/derunudofax.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://fedorahosted.org/lohitIn PDF document text
- https://uploads.strikinglycdn.com/files/ba2a7662-491e-43c2-aa1e-bc78ce31d308/tapped_out_mod_apk_4.41.5.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a2b2a5c1-f107-4527-981b-a95275f15ef7/51421272712.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dc856916-612c-4963-a3fe-2d30a3109ba8/paper_towers_that_can_hold.pdfIn PDF document text
- https://s3.amazonaws.com/tetenifeme/aptitude_sample_questions_and_answers.pdfIn PDF document text
- https://s3.amazonaws.com/memul/cambridge_checkpoints_hsc_advanced_english.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00030a34.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x30A34 | 24508 bytes |
SHA-256: 6595288c6e263a7a5a8048b805659a4f339984d80df5357dd279a1d0a0df1499 |
|||
font_01_sfnt_off000354f3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x354F3 | 4916 bytes |
SHA-256: 491438c56b2ebb3c5f59cad878224aa18441dd586b43943537ca8eaf7f12436a |
|||
font_02_sfnt_off000365ac.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x365AC | 12212 bytes |
SHA-256: 117d3d9718efb43551a9f0d9cc700f8590c76ba35eca02b3f037f24dac7bdf85 |
|||
font_03_sfnt_off00038e59.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x38E59 | 16340 bytes |
SHA-256: 527e5f19db81f75b7c8abea3c72df0b0adb44c94b569f802b6728e21455bb8e9 |
|||
font_04_sfnt_off0003a480.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3A480 | 3380 bytes |
SHA-256: 03b60eb4bf68455ce79a012f1b83a348dcf88c537810c765a013f2911567a17f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.