MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file contains a significant number of embedded URLs, many of which are part of a link farm strategy. One critical heuristic identified a link to a known malicious redirector, suggesting a malicious intent behind the link farm. The ML classifier also strongly indicated maliciousness. The primary purpose appears to be SEO manipulation rather than direct user compromise.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=first+aid+psychiatry+5th+edition+reddit
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://cdn.shopify.com/s/files/1/0436/9691/4600/files/95760580210.pdf
- https://cdn.shopify.com/s/files/1/0433/2794/6904/files/novemenuzipikuve.pdf
- https://cdn.shopify.com/s/files/1/0431/2009/9488/files/95841073344.pdf
- https://cdn.shopify.com/s/files/1/0433/0664/7717/files/bikini_body_pre_training_guide.pdf
- https://static.usrfiles.com/ugd/fe83c3_850c6bd1c2d749b698e88f3cacb91ec0.pdf
- https://static.usrfiles.com/ugd/432b07_b1a1e677fe8a44e1beb8e516cd9ffc64.pdf
- https://static.usrfiles.com/ugd/b8c837_d1cf448b6cbc46a68b31134152d4f845.pdf
- https://static.usrfiles.com/ugd/b8c837_65578ffde2174e11a61e8ae217c79e0e.pdf
- https://cdn.shopify.com/s/files/1/0439/1724/6632/files/rozerukubifezozuto.pdf
- https://cdn.shopify.com/s/files/1/0437/9528/4130/files/543906002.pdf
- https://cdn.shopify.com/s/files/1/0433/5720/8731/files/tuhaf_bilimler_akademisi.pdf
- https://cdn.shopify.com/s/files/1/0431/8851/9076/files/mathematics_grade_12_study_guide_book.pdf
- https://cdn.shopify.com/s/files/1/0437/8905/8206/files/rusajosavisovupukogor.pdf
- https://cdn.shopify.com/s/files/1/0434/4253/6604/files/44640022225.pdf
- https://cdn.shopify.com/s/files/1/0436/1699/3440/files/girotuditenosel.pdf
- https://cdn.shopify.com/s/files/1/0432/9019/8180/files/48438489470.pdf
- https://cdn.shopify.com/s/files/1/0434/7628/7645/files/holy_quran_with_bangla_pronunciation.pdf
- https://cdn.shopify.com/s/files/1/0438/0708/0610/files/86378753040.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000049d4.bin65d6c0dc6ad2300332a0768f7844124665f45de410f6213d8cbf127eec92edfd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x49D4 | 5096 bytes |
font_01_sfnt_off00005b19.bin62d63851651439b0e36acfeb4f2c380916ff323f0c97718317882723ab6638c0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5B19 | 9552 bytes |
font_02_sfnt_off00007bb6.bind1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7BB6 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.