MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a high number of embedded links, many of which point to a known malicious redirector. The ML classifier also flagged this PDF as malicious. The presence of a URL within the document body, specifically 'https://gettraff.ru/aws?keyword=metamorphosis+of+narcissus', strongly suggests an attempt to direct the user to malicious infrastructure. While no scripts were explicitly extracted, the PDF structure and link farm indicate a malicious intent to redirect users.
Machine Learning
- Nyx PDF Classifier malicious score 0.9988
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/aws?keyword=metamorphosis+of+narcissus
- https://cdn-cms.f-static.net/uploads/4365599/normal_5f9158ccebf03.pdf
- https://cdn-cms.f-static.net/uploads/4374703/normal_5f894bb092f71.pdf
- https://buvitefano.weebly.com/uploads/1/3/4/1/134131500/1380a885e8f.pdf
- https://cdn-cms.f-static.net/uploads/4369915/normal_5f8b455e51620.pdf
- https://cdn-cms.f-static.net/uploads/4372399/normal_5f9ca9bb7d427.pdf
- https://cdn-cms.f-static.net/uploads/4368964/normal_5f88537b5f343.pdf
- https://cdn-cms.f-static.net/uploads/4366362/normal_5f9a5b364bce2.pdf
- https://cdn-cms.f-static.net/uploads/4370767/normal_5f91aa9b75751.pdf
- https://nabisipiguges.weebly.com/uploads/1/3/4/4/134432296/sizugefumu.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/53aaa3f0-6684-4f20-8b58-0247d4db2bcf/xejigojito.pdf
- https://s3.amazonaws.com/pazifetanegapu/ncert_maths_textbook_for_class_12.pdf
- https://s3.amazonaws.com/jamokaroxoj/benzimidazole_derivatives.pdf
- https://cdn.shopify.com/s/files/1/0430/3162/5882/files/tk-7_solar_water_heater_controller_manual.pdf
- https://uploads.strikinglycdn.com/files/0ea97ab2-3ecc-4631-8a98-5f29925b60f0/simumokepagepozisaliv.pdf
- https://s3.amazonaws.com/kudowo/buzejizepemevewidigatiw.pdf
- https://s3.amazonaws.com/pusumowi/mason_district_park_trail.pdf
- https://s3.amazonaws.com/tesotiwapax/besame_mucho_guitar_sheet_music.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008ee2.bin0345b7b0fbf1d26f40d077f3bb9c537ffb4d2945dc45e1708bc78ffa6d8d0127 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8EE2 | 5108 bytes |
font_01_sfnt_off0000a01c.bin387d275ba1e1939a12305eedecbc4c7af9de22a64462be6dfaf0e4dc1a0d19b8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA01C | 11756 bytes |
font_02_sfnt_off0000c777.bina542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC777 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.