MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a link that redirects to malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains the same URL, suggesting an attempt to trick users into downloading potentially harmful content. The presence of a large number of external links also points to SEO manipulation for malicious purposes.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=principles+of+business+forecasting+keith+ord+pdf+download
- http://menerima.altoonsultan.com/uploads/1/3/1/4/131406999/zakinixinemapo.pdf
- http://files.lakemichigandance.com/uploads/1/3/1/3/131380236/9302408.pdf
- http://files.wesleyclass.com/uploads/1/3/1/3/131380627/35a601fa8bc4d0f.pdf
- http://tudore.bwvalencia.com/uploads/1/3/0/9/130969868/28dcb71c319714.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://71c943b5-f205-42ab-b77b-05c277a7f3c4.filesusr.com/ugd/3225da_e59109502c8e4fe78743368439b87009.pdf?index=true
- https://03c9e0ef-94a1-43a9-a16b-60f1de1acfcc.filesusr.com/ugd/9ea91e_72ab9a2b0ffe4a6e8bf84175307d3f6b.pdf?index=true
- https://565573ad-b65e-4ff1-8bd9-3dd32aeb0cd4.filesusr.com/ugd/5f226b_d932f3d51bb0458d9231168523d75844.pdf?index=true
- https://e2b3d81e-c0e8-4025-969e-de144ab90861.filesusr.com/ugd/8da65f_2303dddeec6445249a529618bd639ad2.pdf?index=true
- https://437236ff-6a11-49f6-b8af-8b51d3953105.filesusr.com/ugd/031dda_29123ac1f4e94bd78b34e090b4adbbde.pdf?index=true
- https://cdn.shopify.com/s/files/1/0431/0630/4166/files/31519590562.pdf
- https://cdn.shopify.com/s/files/1/0431/6105/9477/files/xufexedorakegumewuvop.pdf
- https://cdn.shopify.com/s/files/1/0428/9911/2095/files/advanced_life_support_manual_7th_edition.pdf
- https://cdn.shopify.com/s/files/1/0428/5916/7900/files/27957812692.pdf
- https://cdn.shopify.com/s/files/1/0433/9436/7644/files/81206520404.pdf
- https://963c18ca-421c-4fed-80f2-1e449c2b6999.filesusr.com/ugd/011e4b_cec88028449449e3ba736e168a33abc5.pdf?index=true
- https://445e3b32-74e3-4f57-82a4-ac988050d83f.filesusr.com/ugd/fb5067_8eaaff10246a4bb5bff4029d2e4ebfae.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004b09.bin37cd9796bcccd764fe1ae869b2f11212ccaccae3d084c357c2330e410c24d267 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4B09 | 5712 bytes |
font_01_sfnt_off00005e80.bin20ab965ff1e896d11849182ea34141a276316baecb454e52b671d6fe6767d9dd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5E80 | 10184 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.