MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file contains a link disguised as a vehicle owner's manual, which is a common social engineering tactic. This link, 'https://ttraff.link/123?keyword=vauxhall+vectra+2020+owners+manual', points to a known malicious redirector. The presence of numerous external links, including this malicious one, suggests the document is part of a link farm designed to distribute malware or phish users. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/123?keyword=vauxhall+vectra+2020+owners+manual In PDF document text
- https://cdn-cms.f-static.net/uploads/4369505/normal_5f88a8713d61a.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4371812/normal_5f88df40d9b88.pdfIn PDF document text
- https://gukepofefefika.weebly.com/uploads/1/3/1/4/131437977/tizuvaxowarovi_dijubujolijogo_zibixuzudenevem.pdfIn PDF document text
- https://gutugifowofe.weebly.com/uploads/1/3/1/6/131606479/8586912.pdfIn PDF document text
- https://wepugimi.weebly.com/uploads/1/3/1/0/131070973/8448799.pdfIn PDF document text
- https://folukufisika.weebly.com/uploads/1/3/1/3/131384255/xigokani-nubakatabuvik-negivufosa-xujagem.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/9a749f1d-015e-4d83-9ed6-d4847ef27a35/vejapak.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e6e0d644-da8d-4e06-9bd1-98521ed7cfae/9177863380.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c1729857-50e5-48ee-9846-b7188ba9a063/modanura.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/405f51fa-43fb-4505-ae78-2a9711b29cab/86833757823.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6efb320b-0ef9-4923-ac19-ed5b8c9b10d8/roduzezoseriveviwafol.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/de398056-9afa-49a8-99b6-80eb91016e13/valifadelovevetata.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5f9b18e9-be80-4a95-95fc-98c4be902940/sekevopiwajet.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/92653739-251b-4030-930d-b761c51651f2/gta_5_karin_sultan_rs.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/338be38b-9d28-4ce7-8f5f-1c7209bb1fdf/lebegilewizusoririvaga.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/06912c02-f70a-4ecf-8ac1-540be131c33e/xidenawaponopefosajukaw.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3bede91a-33bb-4bf2-b814-f0fd3ee1f6e2/47230862523.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fe761aed-370f-4e5e-a18c-4c23981c4fd1/14157079704.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6c2b6383-1f01-4e14-832b-f318694b5ef6/54225343880.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2eebcc89-c440-4237-b7d8-3c8d50ddfb7f/dagazakevexesebupiperix.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5c9ea850-74cc-4b10-a94b-e145444649a5/sutovugamogoguzapewepavi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b545ebc2-0f52-4aff-9bd8-f7da2f6906eb/jaboxugenunule.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006b58.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6B58 | 5500 bytes |
SHA-256: d0dcca347227eb2661b3e7baa5f18a5006627e1e402fddd43dc91da6cb8fe100 |
|||
font_01_sfnt_off00007df5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7DF5 | 10000 bytes |
SHA-256: d29e7363cd667ce0c3453ad36c8e48d83ba73a2fd4bc3bd7a7f370be035dd4d3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.