MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a large number of embedded URLs, many of which point to link farms designed to manipulate search engine results. One critical heuristic identified a link to a known malicious redirector at https://cctraff.ru/strik?keyword=guardians+of+teltoc+offers, indicating an attempt to lead the user to malicious content. The ML classifier also strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cctraff.ru/strik?keyword=guardians+of+teltoc+offers In PDF document text
- https://cdn-cms.f-static.net/uploads/4403414/normal_5f94652c89e61.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4371244/normal_5f948e4bbe9c5.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4409997/normal_5f97a656a8088.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369665/normal_5f886c4c73ad4.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4365555/normal_5f870f74808c2.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://cdn.shopify.com/s/files/1/0266/9818/6937/files/80303981671.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b86528cd-28d5-42cd-bcd0-cd54f062d9ed/28758930323.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/edf484f1-a2a6-4814-93fe-07ddd0785d58/naliwolajedodewogi.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0433/9302/4149/files/cool_games_apk_offline.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ce4bc78d-2057-413d-be97-c501c226eb62/30415896239.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0480/2812/3295/files/wekawokuxamigika.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0484/0095/7608/files/watch_joker_2019_movie.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0438/5023/6054/files/dududazivobobigoxefe.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a0fad1f7-7e35-4cf4-bdd9-78d316191b2b/84691406984.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/016930f0-31da-4ade-a82f-4cb04aaa9421/5708930318.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/817d2940-3ae3-4345-b494-c9f618b1cbb9/nizisawumumejeka.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0483/6802/5751/files/govoburabade.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8090d1ff-bf6b-448e-b5ca-07c5086fd6f7/31579597961.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0496/2762/7676/files/fordson_dexta_diesel_manual.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0502/1643/5891/files/quadratic_word_problems_grade_10_worksheet.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d05ee719-1d63-41f9-b9c5-6b9b3231f847/82749823219.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0486/5533/5574/files/65541693529.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0427/5427/7532/files/rest_api_design_rulebook_github.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0482/3180/9176/files/manual_administracion_hotelera.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0429/6844/9180/files/paroxetina_15mg_bula.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007604.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7604 | 5044 bytes |
SHA-256: ad5f074dda459ffba19c07c1f50ade5c2f62382a7b695cba2d5212b5b928cab7 |
|||
font_01_sfnt_off0000873c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x873C | 12040 bytes |
SHA-256: 7b34e182e264223c16d2e89e2b73be0deaf120120381ab67d03ced07b081dcf0 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.