MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains numerous embedded links, with a critical heuristic firing for a malicious redirector. The document body, though heavily obfuscated, contains a URL that matches the redirector heuristic, suggesting an attempt to direct users to malicious infrastructure. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/pify?keyword=how+to+find+centroid+of+a+right+triangle In PDF document text
- http://vowoxeva.southdevonslinglibrary.com/uploads/1/3/2/7/132740267/feratasupa-savepaxifikano-rusipuzit-kepazeve.pdfIn PDF document text
- http://vevapupe.healthylifecentreedinburgh.com/uploads/1/3/0/7/130775229/5755696.pdfIn PDF document text
- http://sozema.jaqedfitspa.com/uploads/1/3/1/6/131606349/sanas.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/65a012b0-e61a-4258-9e6b-c180e417ef39/83526655726.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b09471a7-86cb-47df-a980-e8c43c451a13/noxemivunidagexin.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9faf97fb-fc13-46ab-a5da-aed5bf190c56/gutetefoluvozoxonabiru.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/41cecb75-d090-4cc0-b9e1-bbc29391758f/19200843984.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/453f64ee-7039-4808-8ab0-52a17f850a84/nujuj.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/065d6975-ae8b-4ef9-888d-d6a8db6b1431/42379668063.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6fd9517d-a649-40ce-94e8-59bed75ebf6a/54194714101.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d41d06bf-b961-472d-b568-c38751c8120d/46124101284.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0465/9413/0085/files/study_guide_questions_for_fahrenheit_451_part_3_answers.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0483/4600/5655/files/foxigaxoxapigubixuzes.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0432/7279/8373/files/nufuzifovevow.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0266/7859/1680/files/topifesepozoz.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0480/8671/2484/files/56807212706.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000071e9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x71E9 | 5156 bytes |
SHA-256: 752d32f303ff0f39ff63f483fa216061df60150a75a9810c6e6bbc93dfd5942d |
|||
font_01_sfnt_off00008383.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8383 | 11008 bytes |
SHA-256: 834f50123b24a2beccc2e7703d825c50baecedb80e9701f94b8d8fb83b4cc089 |
|||
font_02_sfnt_off0000a8db.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA8DB | 16076 bytes |
SHA-256: 1621a87b6bc266bc0e3d5871723ec36fa76dd6d2c9fb76f212020cc469043148 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.