MALICIOUS
214
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'ggtraff.ru'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs, including one to 'static1.squarespace.com'. The ML classifier and ClamAV also flagged this PDF as malicious, indicating a phishing or trojan-like intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/strik?utm_term=truck+mods+for+farming+simulator+19+pc
- https://cdn-cms.f-static.net/uploads/4391037/normal_5fa7e355c1fa1.pdf
- https://dulipitigisol.weebly.com/uploads/1/3/4/7/134717891/77f3618ee.pdf
- https://cdn-cms.f-static.net/uploads/4367275/normal_5f87494eed74b.pdf
- https://zanorima.weebly.com/uploads/1/3/4/6/134624551/82a8139.pdf
- https://static.s123-cdn-static.com/uploads/4366676/normal_5fc934cb88e67.pdf
- https://static.s123-cdn-static.com/uploads/4372086/normal_5fcdb91b66ca4.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://static1.squarespace.com/static/5fc0ebbe5687f52b6b814126/t/5fc4d3c018e72e5fdb701b32/1606734786053/29344752089.pdf
- https://static1.squarespace.com/static/5fc5360b12facd59cec92c87/t/5fc8123390a4f8549d68b23d/1606947380033/laxaxowetogevixofuxi.pdf
- https://uploads.strikinglycdn.com/files/8a12b507-135a-4a9c-baad-f6c8153a72ec/58560032220.pdf
- https://static1.squarespace.com/static/5fc301a1cd1e280355e1eeb1/t/5fcbfe5924c49707d30a3f29/1607204442869/drop_it_like_it_s_hot_haarper_lyrics.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe768b145a8629dc83fda5/1606317709190/16719709518.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbf4958e18c5c478ef1eb6d/1606371672943/que_es_una_tesis.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbcfcdb1491241adc45c27c/1606221020249/pokemon_black_randomizer_rom_desmume.pdf
- https://static1.squarespace.com/static/5fc2886e92c50b1a1e81da22/t/5fce805386731609d52f8aee/1607368790655/6349034900.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000b29a.binaba8aa2fff19db95adf125ffb494e26e1a44e8500da38100b993481188185751 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB29A | 5696 bytes |
font_01_sfnt_off0000c5ec.bin651815c8c61f9b4f533ab96edf17899478f9afc035e783a7f8619ec9d40d1d36 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC5EC | 9724 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.