MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link disguised with a topical keyword ('comic con boston 2020 celebrities') that redirects to a malicious URL. The document also hosts a large number of other PDF links, suggesting a link farm designed to manipulate search engine results or distribute further malicious content. The ML classifier strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=comic+con+boston+2020+celebrities
- http://files.michellenwonderland.com/uploads/1/3/1/3/131383838/xakoje.pdf
- http://fojalox.penrosetutoringandlearning.com/uploads/1/3/1/4/131453175/nunorik.pdf
- http://livoxeka.2ndchanceministrieschurch.org/uploads/1/3/1/4/131407535/jazediwuzopa_mejixexo.pdf
- http://vugubu.sciencebox.co.nz/uploads/1/3/1/0/131069934/67f3221aac8b71.pdf
- http://files.mrsamystaley.com/uploads/1/3/2/6/132680808/c73d46cd733bb1d.pdf
- http://mixof.solutions-guides.com/uploads/1/3/1/3/131380942/sufilovibuwoja.pdf
- http://zudifug.obsidianmals.com/uploads/1/3/2/6/132695675/8094336.pdf
- http://files.ailiniwan.com/uploads/1/3/1/4/131453919/fuzewilijoki-worisavufisite-rexara.pdf
- https://fd61be35-f36a-4aa3-b66f-3aeb94af0478.filesusr.com/ugd/622218_530943acf5574dd88aa2a2a571b61c35.pdf?index=true
- https://c21caa00-c5d3-48ed-ae0c-672fc063a934.filesusr.com/ugd/db80c5_73116cb0a7f643ec857ab8afa799de52.pdf?index=true
- https://5a35db9f-6fcd-46e3-b76e-4f4951020911.filesusr.com/ugd/35ddae_8a1b7c6a67d14845acbe94f798004487.pdf?index=true
- https://e2e1a713-c3a9-4600-9189-770ca586c39d.filesusr.com/ugd/cc1a03_ccf3d0290ee04128908da65c84ced7ab.pdf?index=true
- https://bfe93bda-26d5-4db3-acdc-c6b9d2982876.filesusr.com/ugd/89441e_0666327b5fd04af590ea3779b750fd62.pdf?index=true
- https://25a571e2-e51b-43ce-86e3-63ae08f78e06.filesusr.com/ugd/f390e7_aa43bde62f164cd3bef303ee07699a10.pdf?index=true
- https://92fa9700-08ca-4988-9493-58ad2c6b71c5.filesusr.com/ugd/c1108c_5f52bff80b974f63866e0b03d024139c.pdf?index=true
- https://f376786f-c269-4e3d-ad61-a4959b749662.filesusr.com/ugd/0cd3a8_334f51fccb07421ebb2b0df70d8e481f.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000064a8.bin8129146f9b9d85f00725e453f3d535a909ee913a9c55dd6610b98e90af2ee1ac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x64A8 | 5052 bytes |
font_01_sfnt_off000075c4.bin528fd1e949dbdfedfa671306aa870c3d0676d53171855f00bbe3f47023b8158a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x75C4 | 10772 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.