MALICIOUS
106
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF document contains heuristics indicating it is malicious and uses an SEO redirector for a free-download phishing lure. The document body explicitly mentions 'Ableton live 9 crack ita windows', reinforcing the phishing theme. While no scripts were directly extracted, the PDF structure and embedded URLs suggest an attempt to redirect the user to a malicious site for downloading potentially harmful software.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF carries website-builder CDN document link farm medium PDF_CDN_PDF_LINK_FARMPDF contains many clickable PDF links parked on website-builder CDNs or simple download gateways together with visible ebook, manual, or download lure text. This matches generated SEO document carriers used to route users through untrusted link/download chains; the PDF itself is an inert link carrier.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/123?utm_term=ableton+live+9++crack+ita+windows PDF link annotation
- https://cdn-cms.f-static.net/uploads/4445868/normal_60407cdd32267.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4470839/normal_604703bba408f.pdfIn PDF document text
- https://s3.amazonaws.com/nuselufuzo/ross_tech_vcds_12._12_free.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4389830/normal_5fffd5b80f0bb.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4422372/normal_603362f18b84c.pdfIn PDF document text
- https://s3.amazonaws.com/tujeviwakirawu/desingu_raja_ammadi_ammadi_video_song.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4468843/normal_603ea8e6def85.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4448743/normal_602444d2e5eb6.pdfIn PDF document text
- https://s3.amazonaws.com/fadedosi/blades_of_brim_mod.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4500189/normal_5ff20a2c7f8a7.pdfIn PDF document text
- https://s3.amazonaws.com/gifojuxaxeva/38181432682.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4481515/normal_602d9904536ce.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4424347/normal_602be988bf775.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4481671/normal_5fc56cf712717.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4488092/normal_6012b9fc69ca3.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4421214/normal_6018d76c84c89.pdfIn PDF document text
- https://s3.amazonaws.com/zuvovoxigumuz/gexazeguwidu.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4447084/normal_5ffe48d7b9a42.pdfIn PDF document text
- http://www.ascendercorp.com/In extracted file (font_00_sfnt_off0000f844.bin)
- http://www.ascendercorp.com/typedesigners.htmlIn extracted file (font_00_sfnt_off0000f844.bin)
- https://uploads.strikinglycdn.com/files/99a89e52-5fa5-4ec3-8d1f-3b3627606f2d/best_day_to_take_road_to_hana.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/de4ecff6-3afb-49b8-a1f1-d2ad6ba13d9d/lg_direct_drive_dishwasher_error_code_ae.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f8a035f2-520d-4e68-a405-b5f5003fb28b/early_childhood_cognitive_development_theories.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cf5c06ad-e046-4b5c-b3a2-9599bd83920d/fupomuxokosudifik.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn extracted file (font_00_sfnt_off0000f844.bin)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f844.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF844 | 5432 bytes |
SHA-256: 700e754dee4e1451fd02b7a7e08c056b9d1d3cb109a923f779d58f4242fe6ea1 |
|||
font_01_sfnt_off00010ae4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10AE4 | 11128 bytes |
SHA-256: 8591b82b6d0fd73428cd90df846d4caf4b66e9ce5729ee50eb6e7f929f270d6a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.