MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'traffmen.ru'. The document body, though heavily obfuscated, appears to contain marketing-like text related to lingerie, likely a lure. The ML classifier and ClamAV detection strongly indicate malicious intent, likely phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffmen.ru/strik?utm_term=plus+size+sheer+lingerie
- https://cdn-cms.f-static.net/uploads/4401545/normal_5fac4722d6945.pdf
- https://cdn-cms.f-static.net/uploads/4464869/normal_5fa64d84b1521.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://static1.squarespace.com/static/5fc0c991c6d9645836219624/t/5fc0f0099d79364840af3370/1606479881998/43516755968.pdf
- https://uploads.strikinglycdn.com/files/6f5b5118-bacb-4aa3-8f97-c0f5e6bba6ca/rowogebizowadotuj.pdf
- https://static1.squarespace.com/static/5fc00a5311f6a4198480ec6e/t/5fc12d145147b148045ded33/1606495508757/wegeloxaruxafununinop.pdf
- https://static1.squarespace.com/static/5fc0bdc717e7202640e9644a/t/5fc16217e6d49a06bbc62fcd/1606509080125/karadujovukumedozagexu.pdf
- https://uploads.strikinglycdn.com/files/dd55b313-320c-44ca-9e9f-64b9b24a71db/pokemon_insurgence_post_game_guide.pdf
- https://static1.squarespace.com/static/5fc18edba8793968640cfc97/t/5fc311b1f3de5e49b5c93096/1606619569968/nomipiwakalejijezexewe.pdf
- https://uploads.strikinglycdn.com/files/875625f9-bbe1-4e76-8ba7-e53cb65df1c7/19126977276.pdf
- https://uploads.strikinglycdn.com/files/123c0839-9193-42c6-8256-ef35aba651d3/ielts_cambridge_10_test_3.pdf
- https://uploads.strikinglycdn.com/files/f8beb7cb-df4b-4237-a655-fcebce211d23/foot_pounds_to_inch_pounds.pdf
- https://uploads.strikinglycdn.com/files/47453c0b-1126-4a95-ae19-3a584c52a994/vuzamopumuxipe.pdf
- https://uploads.strikinglycdn.com/files/df0c61ff-e12d-4bff-a63a-7b0fea5b6a5a/pennsbury_school_district_region_map.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000b6eb.bin6c93105d0b1c9684c8dcb1e58afd9bceacd70318b8d77bd1badf4b7091b39061 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB6EB | 4480 bytes |
font_01_sfnt_off0000c603.binf617da5167090eb7844e267de53db4f20f63dd01624c064e4c729898ff053025 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC603 | 12668 bytes |
font_02_sfnt_off0000f0a7.binff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF0A7 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.