MALICIOUS
162
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a malicious redirector link disguised as a download for a photo translator application. It also hosts a large number of external PDF links, many of which point to benign content, suggesting a link farm or SEO manipulation tactic. The ML classifier strongly indicated maliciousness, and the presence of a known malicious redirector URL confirms this.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/123?keyword=triplens+photo+translator+apk
- https://tarirubawapub.weebly.com/uploads/1/3/1/6/131606173/wakorexipo.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/1d44b872.pdf
- https://riwisasivituw.weebly.com/uploads/1/3/1/0/131070703/wulupopopal.pdf
- https://lowizozexide.weebly.com/uploads/1/3/0/7/130776176/9441920.pdf
- https://cdn-cms.f-static.net/uploads/4374185/normal_5f8b7120ca825.pdf
- https://cdn-cms.f-static.net/uploads/4368768/normal_5f8a8b2086d5a.pdf
- https://cdn-cms.f-static.net/uploads/4365619/normal_5f8b6f41d8926.pdf
- https://cdn-cms.f-static.net/uploads/4366029/normal_5f89277059979.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/e5d7ad1c-dc6a-4404-afda-438280b2812d/52671903823.pdf
- https://uploads.strikinglycdn.com/files/1eb9859e-fef2-4a70-ae28-1096af163b21/gawexeruxexojepuja.pdf
- https://uploads.strikinglycdn.com/files/cae627ba-67ee-44ac-aed5-922237a614fc/21028247562.pdf
- https://uploads.strikinglycdn.com/files/cc2986df-438c-4556-9c20-ab2181584a46/wewevud.pdf
- https://uploads.strikinglycdn.com/files/d7d5e789-ee0b-463f-8463-e5dab8f31947/imagenes_sensoriales_do_lazarillo_de.pdf
- https://uploads.strikinglycdn.com/files/ad504ad4-f132-4747-beb6-fcbb14d94c80/23228395895.pdf
- https://uploads.strikinglycdn.com/files/a78adb05-f33a-484c-b7ca-e8c4302732cb/91162055232.pdf
- https://uploads.strikinglycdn.com/files/3dea7ab2-3cbc-405a-88ab-b4250fc32727/53532187420.pdf
- https://uploads.strikinglycdn.com/files/5e0f09a4-0917-4121-b7b7-9ac6eae963b5/27823460783.pdf
- https://uploads.strikinglycdn.com/files/62e7801e-4464-4edd-9719-e5361d6fdf08/lonigedanenifowadepobog.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000064ac.bin8a2bbabca2546842d8cd86954aef0237d15f01dcfb70d3e3e4ee0281d17e21d4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x64AC | 4920 bytes |
font_01_sfnt_off00007551.binad88f6be375ab3b5a1279987a1bdfac7447fda7f94adbf68e007fb5065a9a4b8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7551 | 11332 bytes |
font_02_sfnt_off00009b30.binaa844ae8691b184b22e8641a13f5e4f7be77e035d8e1189434bbea6a0555f82d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9B30 | 16488 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.