MALICIOUS
134
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a link to a known malicious redirector, identified by the 'PDF_MALICIOUS_REDIRECTOR_LINK' and 'PDF_SEO_UTM_REDIRECTOR_LINK' heuristics. This redirector likely serves as a lure to trick users into downloading further malicious content or visiting phishing sites. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/wb?keyword=dream%20a%20little%20dream%20of%20me%20piano%20pdf%20yiruma In PDF document text
- https://s3.amazonaws.com/xanebavifamopez/vukumimolepe.pdfIn PDF document text
- https://s3.amazonaws.com/migivewuwe/definicion_de_plasticos.pdfIn PDF document text
- https://s3.amazonaws.com/vavapekadoliti/calma_emocional_bernardo_stamateas_gratis.pdfIn PDF document text
- https://s3.amazonaws.com/levovod/90333782060.pdfIn PDF document text
- https://s3.amazonaws.com/zuwimadaneb/sufewotep.pdfIn PDF document text
- http://www.ascendercorp.com/In extracted file (font_00_sfnt_off00004990.bin)
- http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off00004990.bin)
- http://www.daltonmaag.com/In extracted file (font_02_sfnt_off00007a2f.bin)
- https://uploads.strikinglycdn.com/files/849c1ab0-f29e-4dcb-bae9-ebb4df683ffb/warband_nova_aetas_guide.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6d4c3b94-1318-48c2-9504-49d559eaa1e5/mifinosasewo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3687d950-fca4-4237-b9d9-c76816c959e4/ragamakosimevarot.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/89820b46-4827-4c4b-b87d-33ea313c1fbc/fabokamupenusuxomepake.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1030d94c-69b3-4467-9b62-67bff7c1295f/86867177662.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a58b03a4-c0aa-4eb0-ab57-84c84b98d2e0/lowopujomegovalate.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d6b61a1e-fbfb-4b4b-8f00-7a2ab4bc4440/podejinemupawe.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/8de24044-47a2-4ba7-892e-2d9ddc398b92/tipos_de_tecnicas_de_recoleccion_de_datos_estadisticos.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e173178b-87b8-49b7-9e92-d397fe1c3aba/11603713006.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5305e62a-9989-404b-8aa2-328567c87bbe/wuluvutaxifomu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7872f6b9-4ef3-45e6-9b80-cc3452b02edc/81603117367.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0304c789-1b68-4e18-97a0-bf0219dcb335/gate_2018_mathematics_syllabus.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b0774772-191e-4842-ba26-ca7c3e073d08/70391794705.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f2288703-c02d-4cce-a0b7-4e539ca28e23/lajatav.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e4cbe8c3-9c30-4380-b460-d803a085be13/lego_book_set.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7b928587-bced-4b1e-a0c7-217539ce7a93/bau_simulator_apk.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off00004990.bin)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004990.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4990 | 4992 bytes |
SHA-256: c2403adb0c7795606f50221b810a65214e9105a59fc6b56e4e86a09cbeddeb64 |
|||
font_01_sfnt_off00005a78.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5A78 | 9268 bytes |
SHA-256: 4288c3f95d0dc3e464366ccadbbaf5ebf7007af449846fdf1c237ec490c3368a |
|||
font_02_sfnt_off00007a2f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7A2F | 4324 bytes |
SHA-256: 8405bb6ca9a6fb718a2e910e1cdde4d74ac2122cab0061dc5f772322db9c7ccd |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.