MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains numerous embedded links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, also contains the URL for the malicious redirector and several other URLs pointing to external PDF files, suggesting a link farm or redirection scheme. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/123?keyword=decor+poached+egg+maker+instructions
- https://cdn-cms.f-static.net/uploads/4379984/normal_5f8ae838eb788.pdf
- https://cdn-cms.f-static.net/uploads/4385231/normal_5f8d950375b83.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5f8853f434c0b.pdf
- https://cdn-cms.f-static.net/uploads/4370264/normal_5f8b66e0f3669.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://uploads.strikinglycdn.com/files/1aa43d54-a137-4e25-9ef6-bc6d6b3dceea/fallout_1_graphics.pdf
- https://uploads.strikinglycdn.com/files/48263336-2a7c-4500-97d6-26d4f0e9cf58/73647037809.pdf
- https://uploads.strikinglycdn.com/files/74ce4f62-7eb1-4029-a567-a59e04fa1685/86882665046.pdf
- https://uploads.strikinglycdn.com/files/58fc1b7a-d084-48d4-b7b9-797a811d332f/lunezasugazazibavob.pdf
- https://cdn.shopify.com/s/files/1/0476/9172/7014/files/lesezojolosufirinadinaw.pdf
- https://cdn.shopify.com/s/files/1/0266/9553/2733/files/pezafewi.pdf
- https://cdn.shopify.com/s/files/1/0492/9031/3884/files/cuttlefish_for_sale_uk.pdf
- https://cdn.shopify.com/s/files/1/0266/8937/2329/files/township_cheats_for_android_without_survey.pdf
- https://cdn.shopify.com/s/files/1/0497/7878/6465/files/mastercool_manual_a_c_hose_crimper.pdf
- https://cdn.shopify.com/s/files/1/0483/4869/2631/files/chess_combinations.pdf
- https://cdn.shopify.com/s/files/1/0430/3205/1873/files/zumerikejelibojapafof.pdf
- https://uploads.strikinglycdn.com/files/b73baf75-35e1-429c-914e-b9b2f5c9830d/77172015436.pdf
- https://uploads.strikinglycdn.com/files/0b3ed9d0-567a-4a9a-ab51-49a80fc70e6b/xelegel.pdf
- https://uploads.strikinglycdn.com/files/eaa2836c-e715-4223-b639-d3bfb4cc6b21/xoxorujeninepe.pdf
- https://uploads.strikinglycdn.com/files/d7d5a96e-08eb-4cbe-a411-cae85e4e40b8/paxovarat.pdf
- https://uploads.strikinglycdn.com/files/85dc3890-b74e-4e03-8986-dd69395066ad/vuzodozazakifuxovi.pdf
- https://uploads.strikinglycdn.com/files/c797004b-5f48-49da-b7ab-ec53f0f13a05/nibajuzudasewezuloloko.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000078b8.bin65bb21c04f96fa122e92c3ad389f32641e73f22ac92d8809f23d031c0e528a16 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x78B8 | 5520 bytes |
font_01_sfnt_off00008b52.bin77bb12a083da9c8e5b00599f963cd762b130d47c06188d99e28b81ddc764a8e9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8B52 | 10548 bytes |
font_02_sfnt_off0000af95.bin8680b359cba86e2f6e9a78cf8c0f9e51b009e062d62f51157c34cd29f25a410b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAF95 | 16340 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.