MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file was flagged by a machine learning classifier and contains numerous embedded links, indicating a malicious redirector or link farm. One critical heuristic identified a link to known malicious redirector infrastructure at 'https://ttraff.cc/wb?keyword=godex%20g300%20service%20manual'. The presence of many external PDF links suggests an attempt to distribute further malicious content or engage in SEO manipulation for malicious purposes.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wb?keyword=godex%20g300%20service%20manual
- http://files.nathandmaki.com/uploads/1/3/1/6/131637104/113a29ffbc9.pdf
- http://files.daniel-craddock.com/uploads/1/3/1/6/131606465/7025495.pdf
- http://files.firstpresnb.org/uploads/1/3/1/4/131438202/butebamovuw_nelaponuvepimam_jalapu_rasarovurikej.pdf
- http://files.peachstatecleaning.com/uploads/1/3/1/8/131871480/4363039.pdf
- http://files.first-contact.org/uploads/1/3/2/6/132681033/cddb01866.pdf
- http://files.greglewisstudios.net/uploads/1/3/1/6/131606798/zeguxolazor_pakowivubolubin.pdf
- http://files.dewarsinnontheriver.com/uploads/1/3/1/8/131856353/4616987.pdf
- http://files.firsttakeagency.com/uploads/1/3/2/6/132681033/ramokonosakel.pdf
- http://files.candicelindsay.com/uploads/1/3/2/8/132814050/zozowinoparakizorixi.pdf
- http://files.firsttakeagency.com/upload
- https://zeravas.files.wordpress.com/2020/07/29044536643.pdf
- https://napipivo.files.wordpress.com/2020/07/tebezez.pdf
- https://vigafekiwi.files.wordpress.com/2020/06/49821554538.pdf
- https://lininolo.files.wordpress.com/2020/06/fafuxiwovubukaze.pdf
- https://cdn.shopify.com/s/files/1/0428/3082/3583/files/23402464981.pdf
- https://cdn.shopify.com/s/files/1/0430/8575/8618/files/31442286919.pdf
- https://cdn.shopify.com/s/files/1/0434/7353/5129/files/koveferolufar.pdf
- https://cdn.shopify.com/s/files/1/0432/4242/2440/files/63425171836.pdf
- https://cdn.shopify.com/s/files/1/0430/3755/6889/files/66497222826.pdf
- https://cdn.shopify.com/s/files/1/0433/1700/2405/files/batalozuxil.pdf
- https://cdn.shopify.com/s/files/1/0433/6009/2309/files/tugarafirobegiwixowowaz.pdf
- https://cdn.shopify.com/s/files/1/0431/1928/0288/files/71838436910.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000077e2.bin823bc0658fc7603a931f49839064d62ed251ca39631aec9708456b6a328212ae |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x77E2 | 5528 bytes |
font_01_sfnt_off00008a95.binfa8c9bf793d5738a2c5513e2ff3eac77e5ea730d52a01150ade4218539ef2d65 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8A95 | 10292 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.