MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains an embedded link to a known malicious redirector, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The ML classifier and ClamAV also flagged this file as malicious. The embedded URL likely serves as a lure to a phishing site or a download host for further malicious payloads.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/strik?utm_term=problem+solution+text+structure+examples In PDF document text
- https://cdn-cms.f-static.net/uploads/4455898/normal_5fa9ac5b620d6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4408478/normal_5fa614f33a575.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://static1.squarespace.com/static/5fc6965cd26ff1194f9b5aa7/t/5fd666a7034a586a4f447d3d/1607886507362/bollywood_wedding_songs_2017_free.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3bd6cd10-486a-4601-b2ee-56412753c4d1/tetilofipekiwalev.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6b3550ec-e4ff-4b3b-87c9-db9b8330e75d/download_youmans_neurosurgery.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0e3e2bac-5603-4f27-89e2-fb1417224c6f/morrowind_doomed_world.pdfIn PDF document text
- https://s3.amazonaws.com/piwupevivotixi/aprilaire_model_700_installation_manual.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7845345a-5f8b-4b14-a547-487164c16d0f/youve_been_framed_actor.pdfIn PDF document text
- https://static1.squarespace.com/static/5fceab1d85e0c3327ca2c441/t/5fd084d93364176a125e4891/1607501018676/43235626636.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc363b5c6d964583631f5aa/t/5fc516391972c46e3c3f170e/1606751802306/16752589797.pdfIn PDF document text
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe1d39cb3e0f577117480d/1606294843150/27513290917.pdfIn PDF document text
- https://static1.squarespace.com/static/5fcdf22f90e5b06becb38742/t/5fd0196989fd2c07d1f6fb88/1607473514294/shoot_em_up_trailer.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d881.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD881 | 5288 bytes |
SHA-256: 2daa39e90e1c71ee6726d4599bc9ca0200fc9859d2d664de8f23224ccb1b0a70 |
|||
font_01_sfnt_off0000ea64.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEA64 | 10708 bytes |
SHA-256: 4d26beed003f17512f0129eff683fc6371bd63fd548170b4c39ed91521689796 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.