MALICIOUS
174
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
This PDF is designed as a lure, presenting a screenshot to conceal a clickable link. The embedded link redirects to known malicious infrastructure, indicating a phishing or redirection attempt. The document's structure and the presence of numerous external PDF links further suggest a malicious intent to lead the user to harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LUREPDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 33 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=vimeo+squidge+report
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://static.usrfiles.com/ugd/b8c837_699892ac357241d5b7e9cd3e6467d43f.pdf
- https://static.usrfiles.com/ugd/d01287_2d918ab6010746178dbaac00bf236482.pdf
- https://static.usrfiles.com/ugd/850f07_499f8db6dd404eef851332a58e452a6d.pdf
- https://cdn.shopify.com/s/files/1/0463/1284/9570/files/edgars_ladies_formal_shoes.pdf
- https://cdn.shopify.com/s/files/1/0428/6670/4550/files/bohemian_rhapsody_partitura_piano_completa.pdf
- https://cdn.shopify.com/s/files/1/0429/0894/2499/files/vawivimolutofonaguz.pdf
- https://cdn.shopify.com/s/files/1/0437/4259/3189/files/muvugugubagokunoneweki.pdf
- https://cdn.shopify.com/s/files/1/0437/3217/2965/files/sivizediperozezek.pdf
- https://cdn.shopify.com/s/files/1/0438/0744/1053/files/download_all_tumblr_likes.pdf
- https://cdn.shopify.com/s/files/1/0441/0081/2952/files/26348727945.pdf
- https://static.usrfiles.com/ugd/b8c837_82af11890f774fe18371512c7932ec58.pdf
- https://static.usrfiles.com/ugd/e73fea_418445926ae24eb3b776fa43c1fcde02.pdf
- https://static.usrfiles.com/ugd/b8c837_1611b782abaa43bbaa46d261452e0f41.pdf
- https://static.usrfiles.com/ugd/b8c837_2a5c2e094fe84ab2b8e5048e66d53fab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00003fd7.bin2f1e7e63852fc5003423ff6f1752ff93230e3f4b2eb5dae752b645e5721efc08 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3FD7 | 4904 bytes |
font_01_sfnt_off00005087.bin5fa5680880ce6dfd613de3e69e75181879b653f335a3a087f84437d57867ad05 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5087 | 7888 bytes |
font_02_sfnt_off00006b4e.bince7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6B4E | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.