MALICIOUS
92
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a link to a known malicious redirector, disguised as an exercise PDF. The ML classifier also flagged this document with high confidence. The embedded URL, https://ggtraff.ru/aws?keyword=arc+back+pain+exercise+pdf, is the primary indicator of malicious intent, likely leading to a further stage of attack.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 2
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/aws?keyword=arc+back+pain+exercise+pdf
- https://cdn-cms.f-static.net/uploads/4385636/normal_5f91f874de685.pdf
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f8744bbd9e2d.pdf
- https://cdn-cms.f-static.net/uploads/4370542/normal_5f8a2293a4331.pdf
- https://cdn-cms.f-static.net/uploads/4387419/normal_5f954e7e071a9.pdf
- https://cdn-cms.f-static.net/uploads/4374374/normal_5f8b6b4ee7976.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/36aeedb6-3a8a-4655-ab41-d9a50da4a9f0/pidivufus.pdf
- https://uploads.strikinglycdn.com/files/bcff7540-2e05-4dec-b203-d6fd9f211581/1012787950.pdf
- https://uploads.strikinglycdn.com/files/88bd604c-086f-402b-a595-bdb6ad5f9372/punazisovu.pdf
- https://uploads.strikinglycdn.com/files/38647177-4b00-4a5e-b67f-00251001b008/45526282802.pdf
- https://uploads.strikinglycdn.com/files/5ba7ab37-1db4-4974-a3fb-4100ab78acb9/bootstrap_studio_themes_free.pdf
- https://uploads.strikinglycdn.com/files/d7d927f8-36ec-4342-8425-68df06640d22/wsus_3.0_sp2_hay_un_problema_con_es.pdf
- https://uploads.strikinglycdn.com/files/dacd3347-cf4d-4cd7-b89c-74bdf67ef0b1/fogelasodo.pdf
- https://uploads.strikinglycdn.com/files/64a57b21-dfab-49a4-a586-cd15e2d6073e/xojogaduvunebozoxopusutal.pdf
- https://uploads.strikinglycdn.com/files/073d4c1d-c443-4b7d-b6c0-2dd14f3f0078/62885285563.pdf
- https://uploads.strikinglycdn.com/files/bd717ae1-869a-4c16-935e-20316eb4fd44/ruwelajozatebinimawixax.pdf
- https://uploads.strikinglycdn.com/files/1579b77d-ebc2-48a8-945a-4055abcf331e/33738557673.pdf
- https://uploads.strikinglycdn.com/files/84593b82-6303-49c5-b3ed-407c151f8ce4/lindor_chocolate_flavor_guide.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007b87.bina9062832657f2ed9c7d63408f0249db99a51d7543c7f5061bee8207a3960b76a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7B87 | 5380 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.