MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document contains a mass of external links, including a known malicious redirector. The document body, though obfuscated, contains the URL 'https://gettraff.ru/strik?keyword=editable+pdf+creator', suggesting a lure to a malicious site disguised as a PDF creator. The presence of numerous links to external PDFs and the ML classifier's high confidence indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/strik?keyword=editable+pdf+creator In PDF document text
- http://files.yonelfashion.com/uploads/1/3/0/7/130776148/7273542.pdfIn PDF document text
- http://jelusuba.jcovercomersministries.net/uploads/1/3/1/4/131438562/daligudebesexim-fuwatuk.pdfIn PDF document text
- http://files.catryanmedium.com/uploads/1/3/2/6/132695636/kubotaxowiwi_jukizowarim_timoxob.pdfIn PDF document text
- http://mijar.stfranciscentre.net/uploads/1/3/0/8/130814328/bozixabos_rofufojasipu.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/53e31ef1-af42-4b02-a7ce-4b82e4a8cf1c/16916029349.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d677f213-4116-4814-85c1-d229e83123a3/makigodavuburelapinul.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f026916f-c1c3-45de-893c-2b5a964410db/doradifa.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/906c6337-61aa-4a56-8b6b-576f7df31a68/zisazewadega.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9ef357ee-e8de-45f3-8fe1-12992fac1213/7747274936.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/02e6b4c5-3869-4c02-9d37-f739a743a3cf/82321969811.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/090ad5a5-bb45-4279-89b1-e43a23c6ef38/wivopibaguvegifubetugaf.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f30532f6-d616-4119-9596-c85d62588013/8130037324.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/82d5bc9a-dfec-4b88-bb7e-733b1d0f5e9c/99042956039.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000048b9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x48B9 | 5068 bytes |
SHA-256: 6cfac06948648da29eead33e772e8978f1e371b516d1d6a91e8fa1b5860249b6 |
|||
font_01_sfnt_off00005a04.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5A04 | 9424 bytes |
SHA-256: 7ea61ba35eb106f619d89851c3883cb906d1589319991080a86f513e98aaf6b5 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.