MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains embedded links that point to a known malicious redirector. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains a URL that matches the malicious redirector found in the heuristics, suggesting an attempt to lure users to a harmful site. No scripts were extracted, but the presence of multiple external links indicates a link farm or redirection strategy.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/strik?keyword=pathfinder+lantern+king In PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/a96e9dc5-ad26-4cd9-b550-5490de9fa854/25640152285.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0bc022b7-b0c4-441b-bc76-215681992181/mtv_unplugged_nirvana_full_album_download_zip.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b6178aa8-1d11-4ea2-bc25-b8966db4fb72/concepto_de_competencia_segun_autores.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/48f96f5b-255a-450d-9568-e7b06a249351/94469768703.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0484/3012/1112/files/28597644885.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/799dc183-3e9c-4b93-be3f-435c95e9fa0f/38739814742.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/aa0322a4-2c2e-41dc-b525-d03594aa6a6d/96542469662.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3c9b82bf-4c7e-4022-ad4e-c791f2cc793b/deezer_premium_code_generator_no_sur.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d037dc2e-eb36-446d-a42e-ae0160da0c9f/52800994379.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fdfb6804-06b8-4902-af00-09091e95c1c0/34756609944.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e6439306-49a2-4c14-894f-e4adae49439c/84860017158.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/784c7c50-f95d-46bb-9758-9c61ccd5f7f3/21984388388.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d181ac6d-9dfe-4ffb-967b-1755c9bcf068/sztr_angol_magyar.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2be611f4-3eed-4598-8bec-e629862e2418/81799587152.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/71992935-5c0f-48c6-9a57-0939076464e5/54297037694.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9ed9b244-01aa-4eba-92a4-aedc39afa5be/tawibavoradu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/455de801-3ec6-4173-aa88-41a307ce96d9/suketesagusukaji.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b8aeb8d6-861f-409d-af57-1a99dc9ef0b0/90630379251.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006f11.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6F11 | 5056 bytes |
SHA-256: 86ebb140f88f9dee6e0e5cbb4bdcf9fb8c7c06d0a32c6e23137c2c5feccb893f |
|||
font_01_sfnt_off0000803a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x803A | 11204 bytes |
SHA-256: 4f32f437d48cb73849df25bf82478bec1f814c1e424e1f63b6d514ffdb048324 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.