MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains embedded links that redirect to a known malicious URL, suggesting a phishing or scam attempt. The document body, though heavily obfuscated, contains the same malicious URL. The presence of numerous external PDF links further indicates a link farm or SEO manipulation tactic to distribute malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9807
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/strik?keyword=mechanics+of+materials+8th+edition+solutions+gere In PDF document text
- https://sakukavazu.weebly.com/uploads/1/3/1/3/131379729/zefor.pdfIn PDF document text
- https://milavigik.weebly.com/uploads/1/3/2/8/132815866/98e6428979c0.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/9894c1f6-fa89-4d77-83b7-a81f8ca99447/kusemikabodano.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c0ded99c-0364-4d7b-acda-6d85b2493f32/xodivifowiwurajet.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f6340535-6b12-4cd7-857a-e44b99cf7f62/fundamentals_of_abnormal_psychology_by_ronald_j_comer.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/93dbabc8-5a85-4199-8199-22f54850f69a/11207306644.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e7f552bd-66b3-4e1f-b753-7e30d6e0ce9b/1094157476.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bac879d6-b2c1-4892-8e70-efaab4ace1bb/tolokojozaso.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0f095d59-6e36-4b27-b789-6bd556f3c8cb/somopijolinap.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6a03655e-bf5d-4e3b-8a2d-90dcd4d502b8/niwedakanotesa.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/79dc5e9c-1fad-48de-8d12-c6ec79594db1/surajimegoledipejugunuje.pdfIn PDF document text
- https://s3.amazonaws.com/fuwawibu/aiims_bhubaneswar_recruitment_2017.pdfIn PDF document text
- https://s3.amazonaws.com/henghuili-files/nombre_alcoro.pdfIn PDF document text
- https://s3.amazonaws.com/wemupajese/probability_important_formulas.pdfIn PDF document text
- https://s3.amazonaws.com/buponuwebi/kuvumojogobogagerebup.pdfIn PDF document text
- https://s3.amazonaws.com/gupuso/gowugibefidowaziro.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0481/7856/1178/files/41309187203.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0428/2286/0956/files/letariboletokelosuli.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0481/1813/6995/files/zedimetofeziletijitusor.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0435/5696/2467/files/fedef.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0266/8045/9456/files/since_you_asked_maurene_goo.pdfIn PDF document text
- https://s3.amazonaws.com/felasorarabipis/ielts_academic_practice_test_with_answers.pdfIn PDF document text
- https://s3.amazonaws.com/susopuzupure/japanese_children_s_books_for_beginners.pdfIn PDF document text
- https://s3.amazonaws.com/dazinibonofobi/ankle_joint_mobilization.pdfIn PDF document text
- https://s3.amazonaws.com/divexikav/bed_psychology_books_in_telugu_free_download.pdfIn PDF document text
- https://s3.amazonaws.com/sukedil/aprendizaje_basado_en_proyectos_ejemplos.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001c2ee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1C2EE | 5632 bytes |
SHA-256: 7b59042c6dee2240dc4323ac031076bc4baf2d140fddc20339dc761c79765b1a |
|||
font_01_sfnt_off0001d5b4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D5B4 | 6220 bytes |
SHA-256: 131f63b11c0c151fe50e1eb401d539047cd4dfa4bea0978b0a7b3d04d6e440d4 |
|||
font_02_sfnt_off0001e4c5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E4C5 | 13788 bytes |
SHA-256: 64ae528b2e0c88b24c70307fa0c5cefdc8f0208f385f0738f327aa879c4ad4c6 |
|||
font_03_sfnt_off000212af.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x212AF | 16304 bytes |
SHA-256: f7ab22c5676f0fb992585cfcb618891f6e5f08277b409478d1880cb963c9fa38 |
|||
font_04_sfnt_off00022835.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x22835 | 6152 bytes |
SHA-256: 4ed3a3ccf4c9be320d00119979a701fe787e6d203e0dc076c13db6f913287dcb |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.