MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous links, with one critical heuristic identifying it as a redirector link to 'gettraff.ru'. Another heuristic flags it as a link farm, indicating a potential SEO poisoning or spamming campaign. The document body, though partially garbled, mentions 'Magica travel agency match 3 puzzle games', suggesting a lure to disguise the malicious intent. The presence of embedded URLs and the ML classifier's high confidence score support this assessment.
Machine Learning
- Nyx PDF Classifier malicious score 0.9992
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/strik?utm_term=magica+travel+agency+match+3+puzzle+games In PDF document text
- https://pidofuvu.weebly.com/uploads/1/3/0/7/130739764/2860498.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/a639147f-2a10-4cd3-9fe4-6c6d39c1e9f8/44007985024.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2b100535-98fe-4684-a697-01202ca52f7b/89866175799.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b37b21f0-463f-4bae-acf0-abef6ffd86d6/bumupuxivixe.pdfIn PDF document text
- https://s3.amazonaws.com/posufij/gonepotozuzago.pdfIn PDF document text
- https://s3.amazonaws.com/roxawo/political_cartoons_activities_for_american_history_answers.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc55f48bdb33045eee0080d/t/5fc6593df3de5e49b53dfdb1/1606834493172/rechargeable_batteries_deals.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b3360c46-9d0b-4fd8-bdf4-487f508863f6/estado_de_puertos_litoral_directemar.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f8fafe12-8f6f-4762-91c4-c9893a8bd5d7/radazusojokuviz.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc58a1012facd59cecc81e0/t/5fd645a6481cfa31adc37565/1607878060345/66748391252.pdfIn PDF document text
- https://s3.amazonaws.com/lukepepe/dnd_5e_scholar_pack.pdfIn PDF document text
- https://s3.amazonaws.com/patotale/android_root_apps_no_pc.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/68c16476-b3d7-47cc-9d0e-cdb7f8985fb3/kileguforidolajodo.pdfIn PDF document text
- https://static1.squarespace.com/static/5fdcb81cb919dd0c3e451148/t/5fdd1412365f8f1a3b11751d/1608324116074/95489703685.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e7ee.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE7EE | 6676 bytes |
SHA-256: 657ecd41de71d6cc26ea63214dcfece046f6447d6d4f661ddd1c7c509279b1e4 |
|||
font_01_sfnt_off0000f8c4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF8C4 | 5728 bytes |
SHA-256: 21ebbbc17c24884e0e83488c8b18d08fdb019e66f6c1c3353272e64ff2d5f015 |
|||
font_02_sfnt_off00010c40.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10C40 | 14564 bytes |
SHA-256: 0077cb9289f085bdaecdf0d80f03d08afc20588f942101947f7bb42f6abdf005 |
|||
font_03_sfnt_off000139c1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x139C1 | 10780 bytes |
SHA-256: 2019897ec231468af7f19c3c96e036786f22c9baff5c29a14d731f36ecbe7b66 |
|||
font_04_sfnt_off00015eac.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15EAC | 16036 bytes |
SHA-256: 52db30b66cfb76898988bc7c6ed152514c301740808ab95bec9c68e49df23550 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.