MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link that redirects to a malicious domain, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains text suggesting a lure related to a 'precalculus summer review packet answer key'. The PDF also hosts a large number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic, likely for SEO poisoning or to distribute further malicious content. The ML_NYX_PDF_MALICIOUS heuristic strongly supports the malicious classification.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=honors+precalculus+summer+review+packet+answer+key
- http://nepin.blazingharvestvirtualagency.com/uploads/1/3/0/8/130814408/723b7a1884ab.pdf
- http://mupez.deliver-us-from-evil.com/uploads/1/3/0/7/130776208/berawiwaga.pdf
- http://files.cassandrakgolden.com/uploads/1/3/1/3/131379530/9fc4b114cebce.pdf
- http://files.sweetnnaughty.ca/uploads/1/3/2/8/132815318/ce0cb.pdf
- http://files.hanooie.com/uploads/1/3/0/7/130739731/rofawuvu.pdf
- https://3dc043ad-8abf-44f4-b992-941a63154022.filesusr.com/ugd/b8c837_d23a8c229fdf41559733f7d8c8fedd2b.pdf?index=true
- https://910f8a61-4328-4eb4-89c6-8704f12ec713.filesusr.com/ugd/704566_9f746f6e3681418db78e2543bde95179.pdf?index=true
- https://8f9c7b3e-4b07-4e1d-b885-ba4c7f795097.filesusr.com/ugd/5c8b2f_37a157b72d964920b9133facd5ca7e57.pdf?index=true
- https://0b1f8010-0b94-47cd-bda0-18ad10f4fba3.filesusr.com/ugd/3225da_07d38eedd0cd433d800c31bd30456fb5.pdf?index=true
- https://7550a040-178e-4855-bfd3-ce36ee5f95e1.filesusr.com/ugd/bcfc12_b893a85468694436b9c8162bb994cfd0.pdf?index=true
- https://afdce74c-b476-4936-93db-645b719519be.filesusr.com/ugd/8a5fcf_f35ba18edd27488c8f1c9fb8c1f75fc5.pdf?index=true
- https://742c41d0-930e-4c8b-a947-78f6f32814b4.filesusr.com/ugd/4c1554_3cc1af28e1794f97a2fec2f8dc42c8c8.pdf?index=true
- https://12917b3f-9184-4e1d-b104-951db35ecc29.filesusr.com/ugd/44b221_f452a11bfb8a4c5f819f0d0d51b00174.pdf?index=true
- https://d3ee525b-8b51-4638-a6f6-ea3c84f8f35f.filesusr.com/ugd/cdfdba_6a2b6b8e94a6406bbe08216a99538ff8.pdf?index=true
- https://4638cb7d-562e-486d-b77d-9aa121411159.filesusr.com/ugd/eb6612_c5260682c2b74eedba131c146e786c31.pdf?index=true
- https://c2985419-3ed3-4647-946c-8ab7d9c3abb9.filesusr.com/ugd/314c35_bcb04dfc91b14853b448f94da135ae54.pdf?index=true
- https://0bc9768f-85c2-4c70-87f7-155b099d7516.filesusr.com/ugd/e2c6c1_0fff557e395b488d8c13901b3a4ef807.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://c2985419-3ed3-4647-946c-8ab7d9c3abb9.filesusr.com/ugd/314c35_bcb04dfc91b14853b4
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000063cb.bin3e50bdaa293d927ba748c1393fd9a5d7d2471e7db0e9b9e5387af1dffa1b34e2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x63CB | 5240 bytes |
font_01_sfnt_off00007595.bin10349332a0c0fc2d92de27b850c878ed73d81dc5cc8cf72c3deeec5c3bf504d0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7595 | 10804 bytes |
font_02_sfnt_off00009a59.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9A59 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.