MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a link farm and a direct link to a known malicious redirector, suggesting an attempt to drive traffic to malicious infrastructure. The document body, though heavily obfuscated, contains URLs that appear to be part of a SEO link farm strategy, likely to disguise the malicious redirector. The ML classifier strongly indicates maliciousness, and the presence of embedded URLs points towards a phishing or redirection attack.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=multiplying+decimals+worksheets+fifth+grade
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cdn.shopify.com/s/files/1/0430/9689/9745/files/lopejekewiwureponin.pdf
- https://cdn.shopify.com/s/files/1/0431/6105/9482/files/wetevasubojozij.pdf
- https://cdn.shopify.com/s/files/1/0431/6125/6096/files/wivarofawixirikijukatavot.pdf
- https://cdn.shopify.com/s/files/1/0431/4143/1464/files/barcode_software_full_version_free.pdf
- https://cdn.shopify.com/s/files/1/0435/4146/3204/files/303741812.pdf
- https://static.usrfiles.com/ugd/87ad98_c07f795dff6e4103a65bd01479c25e9b.pdf
- https://static.usrfiles.com/ugd/d31907_6cc067f54ed24f4e9c046f3450c05a55.pdf
- https://static.usrfiles.com/ugd/1b8612_7db4c6134c1b4abdb4066a28a71afaa4.pdf
- https://static.usrfiles.com/ugd/90661f_e02402c6f72b4bd4aebe40859db35790.pdf
- https://static.usrfiles.com/ugd/ba3095_c156ccdf69bd48f9b0797cf1b09680e5.pdf
- https://static.usrfiles.com/ugd/9edd50_12094320baca4d75989168a75e20c555.pdf
- https://static.usrfiles.com/ugd/1fa6dd_8ca25d0756694850930c6a8da91a3a79.pdf
- https://static.usrfiles.com/ugd/724fb5_0f0fb85504314c0292866b8fd45a24c1.pdf
- https://cdn.shopify.com/s/files/1/0429/8702/8641/files/30104708127.pdf
- https://cdn.shopify.com/s/files/1/0431/7777/1164/files/discord_animated_emoji.pdf
- https://cdn.shopify.com/s/files/1/0431/2681/6932/files/33907742294.pdf
- https://cdn.shopify.com/s/files/1/0439/2953/4632/files/barbie_costumes_ideas.pdf
- https://cdn.shopify.com/s/files/1/0431/3038/8642/files/42749752154.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000062f5.bin46fe530def916774ad14df0040d31e07db29595eed74ed7627a0343bd181b3ac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x62F5 | 5832 bytes |
font_01_sfnt_off000076ca.bin109d230d2e3156b298ec7d334a4c18e0f30e509c72a869a28ee92fee294c3ca9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x76CA | 10444 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.