MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains embedded links, one of which points to a known malicious redirector infrastructure. The document body, though heavily obfuscated, appears to contain keywords related to popular games, likely as a lure. The presence of multiple embedded PDF links suggests an attempt to create a link farm or distribute further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/123?keyword=pokemon+yellow+mew+glitch+lavender+town
- https://towetebofipu.weebly.com/uploads/1/3/1/4/131437669/0a325a.pdf
- https://vuguzakinizole.weebly.com/uploads/1/3/4/4/134493236/769e024dc.pdf
- https://baletepo.weebly.com/uploads/1/3/0/7/130776023/jebab.pdf
- https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/7904132.pdf
- https://vemifibu.weebly.com/uploads/1/3/4/3/134354414/wowarexoxige.pdf
- https://gemaxudemaxepeb.weebly.com/uploads/1/3/1/0/131070646/15e8d3c62b9a40e.pdf
- https://bubixoduxufito.weebly.com/uploads/1/3/1/0/131070588/2d5335c4874eff.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cdn.shopify.com/s/files/1/0504/8998/3136/files/leisure_time_activities_worksheets.pdf
- https://uploads.strikinglycdn.com/files/9a05e328-268d-4dc2-b583-e306186ff908/95017218133.pdf
- https://uploads.strikinglycdn.com/files/2257ce2c-19f3-4e54-9fdf-c3723ed558a6/morevoj.pdf
- https://uploads.strikinglycdn.com/files/cfc30d77-c973-4be8-9feb-88cb065653ac/25848043852.pdf
- https://uploads.strikinglycdn.com/files/a6e40c5c-e8c7-4594-8c39-77809d7f7af9/73673379775.pdf
- https://uploads.strikinglycdn.com/files/dee5bdab-d5e5-4846-a136-afb5f7abdca4/zolumanibipisetivifi.pdf
- https://uploads.strikinglycdn.com/files/b042e445-da45-4d00-996f-cebef0e5fcd1/vegavikurowerulif.pdf
- https://uploads.strikinglycdn.com/files/b45f15df-0a3f-4643-8bed-c33ac488a664/kordil_edms_tutorial.pdf
- https://uploads.strikinglycdn.com/files/713d59ab-4be9-407b-bc67-d9a245cae8b9/76778723096.pdf
- https://cdn.shopify.com/s/files/1/0492/2484/3420/files/gavuzifugamoxov.pdf
- https://cdn.shopify.com/s/files/1/0438/8775/5432/files/spirit_bond_ffxiv.pdf
- https://uploads.strikinglycdn.com/files/1bb9cb6f-d1cb-44c6-8f9b-042b83c653bf/23243551296.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000a238.bin153cb78d4a1fa6da874a669a512ae8b7fda45871ae40ea86962ab7137767f04a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA238 | 5132 bytes |
font_01_sfnt_off0000b43b.binb213910cb61bd6b5ee22b313b4fea4dda19983c2d1b7fa798b73c621b1abc477 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB43B | 5496 bytes |
font_02_sfnt_off0000c6e9.bin05717e664b4d3cd3d381fa25f19cb4cef7251504cc9455ba02aff0ef818c9e90 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC6E9 | 11052 bytes |
font_03_sfnt_off0000ec54.bin12bdfdd26b42687ed6d6e4673084773943fc64d80ea302008a05158b1f99f3df |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEC54 | 16068 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.