MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a malicious redirector link disguised with a lure about Prince concerts. This link leads to a link farm of numerous other PDF documents, indicating a coordinated effort to distribute content through a network of redirectors and hosted files. The ML classifier strongly supports the malicious nature of this PDF.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=prince+concerts+in+atlanta
- http://sutuvar.pcgeeksonthego.com/uploads/1/3/2/3/132302720/e15f5.pdf
- http://ratevov.enactusguelph.ca/uploads/1/3/1/1/131164239/tebevi_bivunozipewuwaz_meputoba.pdf
- http://noximug.linie-e.com/uploads/1/3/0/7/130739377/taxarujeza-kuduku-jodipelexofatux.pdf
- http://xasokilar.mikeharrisdesign.net/uploads/1/3/1/6/131636665/86d077.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/68769425665.pdf
- https://cdn.shopify.com/s/files/1/0430/6986/6141/files/varasivixaganibogutore.pdf
- https://cdn.shopify.com/s/files/1/0430/5548/0981/files/fisica_atomica_y_molecular.pdf
- https://a9acbccc-7893-49f6-96ca-fd4d798bdfb0.filesusr.com/ugd/bc84a3_a6c2f80457ae4852bed87e85296d94cf.pdf?index=true
- https://5cf9e869-a451-4fe4-927c-43c12e8ff72d.filesusr.com/ugd/b3318b_fc8796623fe1476aa862f1113b14980b.pdf?index=true
- https://0cd7cc6f-edf5-4afb-ad5d-6d2d5c105ab0.filesusr.com/ugd/1cc7e8_bf0e33ba4f4e4db8a02a861c63fc0bda.pdf?index=true
- https://01e9c1c1-69cc-40d4-8971-08f65d73a734.filesusr.com/ugd/a382ee_892f5bd439e44345a0bfffd67eae248b.pdf?index=true
- https://d67302e5-4c39-42ac-ba0b-fb65de753d8d.filesusr.com/ugd/f91cf1_e892e85ac8a54975ba09686507f6b80d.pdf?index=true
- https://fbab0a7a-a9e4-4641-83a7-127d35be8cfa.filesusr.com/ugd/f68081_eda5aaa5b6c1453cb992d1888eca2478.pdf?index=true
- https://56f4de74-18f6-4d27-87d7-b97ccdb42999.filesusr.com/ugd/dfb5f8_e0943bbbfdb040558351040921536232.pdf?index=true
- https://505e4a3f-da3b-4666-93cf-5bd05be84383.filesusr.com/ugd/17159d_83018becf6ed405b91372ce3c2c64799.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://505e4a3f-da3b-4666-93cf-5bd05be84383.filesusr.com/ug
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004550.bine5b49ec87d884068b668cd36b14000d558194d94597d22ea792f344c44b0d207 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4550 | 4792 bytes |
font_01_sfnt_off000055a6.bin95d52d6611ada5c3eaaa21439ff73daf8358425e875da897e1b1233b54a39fe8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x55A6 | 9416 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.