MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a clear lure for a 'robux generator' and embeds multiple links, including one to a known malicious redirector. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK confirms the presence of a malicious redirector, and PDF_SEO_LINK_FARM indicates a large number of outbound links, suggesting a link farm or spamming operation. The ML classifier also strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/123?keyword=robux+generator+apk+no+human+verification
- https://cdn-cms.f-static.net/uploads/4370525/normal_5f912a2e79781.pdf
- https://cdn-cms.f-static.net/uploads/4370307/normal_5f914eb1252be.pdf
- https://cdn-cms.f-static.net/uploads/4368485/normal_5f89703cd715a.pdf
- https://cdn-cms.f-static.net/uploads/4370525/normal_5f884979bc66b.pdf
- https://cdn-cms.f-static.net/uploads/4385207/normal_5f8d1aacb46a5.pdf
- https://cdn-cms.f-static.net/uploads/4381529/normal_5f8e3e56f1e5d.pdf
- https://cdn-cms.f-static.net/uploads/4370052/normal_5f8ed6eb77c23.pdf
- https://bilewobadazape.weebly.com/uploads/1/3/2/6/132695578/7696805.pdf
- https://kuvofexe.weebly.com/uploads/1/3/1/1/131163751/lodaxevizisufuvaza.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://cdn.shopify.com/s/files/1/0497/5978/1023/files/kubovarevoxa.pdf
- https://cdn.shopify.com/s/files/1/0484/6996/7013/files/wechat_application_download_for_android.pdf
- https://cdn.shopify.com/s/files/1/0468/3363/1425/files/digital_certificates_explained.pdf
- https://cdn.shopify.com/s/files/1/0498/5412/0103/files/76096502415.pdf
- https://cdn.shopify.com/s/files/1/0498/9127/9030/files/zewozawojulutitodevilut.pdf
- https://cdn.shopify.com/s/files/1/0266/9399/2640/files/19506716090.pdf
- https://cdn.shopify.com/s/files/1/0476/1452/5596/files/96150232903.pdf
- https://cdn.shopify.com/s/files/1/0481/4694/0065/files/15827140638.pdf
- https://cdn.shopify.com/s/files/1/0432/9121/3990/files/puzzle_and_dragons_z_monster_guide.pdf
- https://cdn.shopify.com/s/files/1/0431/3487/7853/files/bojozobevofozu.pdf
- https://s3.amazonaws.com/memul/bulleh_shah_biography.pdf
- https://s3.amazonaws.com/subud/45819715906.pdf
- https://s3.amazonaws.com/zuxadol/81981027255.pdf
- https://s3.amazonaws.com/zarelusipofox/fusuremutotosanawawomob.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007368.bin996369bc989dffb6f09e7748810d510fc59758823a6b7b0863d588180fde14b5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7368 | 5440 bytes |
font_01_sfnt_off000085c6.bin6e5de5c6bcb7fdd8c5ca0d25823a8f80e6c764803c1b732dbc9c425a5c0f8ea5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x85C6 | 2092 bytes |
font_02_sfnt_off00008f6c.bin5c91d3ed9ec0eb0ad5b983926224d729470cd4c03fec49a8b14475aeeabbcd33 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8F6C | 11380 bytes |
font_03_sfnt_off0000b495.bina542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB495 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.