MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a large number of embedded links, many of which point to a redirector URL identified as malicious. The document body, though heavily obfuscated, contains text suggesting it is a worksheet answer key, likely a lure to encourage clicks on the malicious links. The presence of embedded URLs and the ML classifier firing strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=chemistry+reactions+worksheet+answers
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://6d76ef7d-8e03-49bc-be8c-cc1e23a2af20.filesusr.com/ugd/3d514e_e091f056149649ce8468b16e7cce66a7.pdf?index=true
- https://5813023e-df3c-4941-918e-c83951cfd750.filesusr.com/ugd/2f7489_b0ab2561eea140f0936bed02cdaedd2a.pdf?index=true
- https://84ab88cb-bb14-48c4-bcd5-36b1a8cd15ff.filesusr.com/ugd/7dfe85_6bd80a05ab5b4fbeb00278b970fda244.pdf?index=true
- https://6e8c98c5-66cb-4079-b96d-4fb05596901a.filesusr.com/ugd/0049ca_29d3091e193247dba2ee65ea7e017278.pdf?index=true
- https://0d759238-7e1e-4cec-9d64-f16cdf268709.filesusr.com/ugd/02ccf7_6ffaa140d3624291951c3f1c646259d2.pdf?index=true
- https://07ed169d-f166-451b-86fe-9bac6989c938.filesusr.com/ugd/54dfea_93b57c22c4ac49b498c384fa1caed2d0.pdf?index=true
- https://043b033f-1a9a-4ecb-908e-81353e0986f4.filesusr.com/ugd/0df15e_491b5736fe274159b95437038bd889af.pdf?index=true
- https://e9765cc6-58ad-4b24-994f-7c42b0c5a04d.filesusr.com/ugd/bf57b5_080f0a35c6ea4d37960421e8515ca4c9.pdf?index=true
- https://498b408a-669f-448f-b732-35b262930ebc.filesusr.com/ugd/23a6c3_3488dee78ea24edcb0d0ea6acbef51b5.pdf?index=true
- https://4ab9fd42-5bdb-4f4d-b7be-224a3db7d7b8.filesusr.com/ugd/2b25b5_122ca1b7f41e41659d50b2b74347bb76.pdf?index=true
- https://700406d4-fde8-4470-b7f6-09abbfec2f7b.filesusr.com/ugd/b56239_42f17346d73f4b9ebd520142ad3e0f2d.pdf?index=true
- https://cdn.shopify.com/s/files/1/0431/3966/1986/files/scholarship_2019_to_2020_india.pdf
- https://cdn.shopify.com/s/files/1/0435/5719/1843/files/beneficios_de_la_zanahoria.pdf
- https://cdn.shopify.com/s/files/1/0435/3776/0408/files/fairness_and_accuracy_in_reporting_twitter.pdf
- https://cdn.shopify.com/s/files/1/0438/2860/9186/files/fofewu.pdf
- https://cdn.shopify.com/s/files/1/0434/1907/4712/files/hash_table_implementation_in_java.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000069bc.bin4017f999cc40e085b75d8e6d8ddc10200b8d7ff091d45d36978cfe8b337ddc97 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x69BC | 5172 bytes |
font_01_sfnt_off00007b32.bin85ded28ce680ae20bdfb39df9c35c3af1e863cc934928eb727bc2f9547d21725 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7B32 | 9804 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.