Malware Insights
This PDF file was flagged by multiple heuristics as malicious, including a critical finding for linking to known malicious redirector infrastructure. The document contains a large number of embedded links, many of which point to benign-looking but potentially SEO-farmed content, while at least one URL is confirmed malicious. The primary malicious URL is https://traffine.ru/strik?utm_term=crossword+puzzles+online+free+new+york+times, which likely serves as a redirector to further malicious content. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://traffine.ru/strik?utm_term=crossword+puzzles+online+free+new+york+times In PDF document text
- https://cdn-cms.f-static.net/uploads/4412773/normal_5fab5d12662f1.pdfIn PDF document text
- https://pobivizitonep.weebly.com/uploads/1/3/2/8/132815986/fepije-mofilebanitamow.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://static1.squarespace.com/static/5fc30874df132613bbcb9d36/t/5fcaa8e828f1282c708f5299/1607117032757/best_way_to_learn_javascript_for_web_development.pdfIn PDF document text
- https://s3.amazonaws.com/jebokizez/calculating_intake_and_output_worksheet_answers.pdfIn PDF document text
- https://s3.amazonaws.com/xijuxosisomuna/wixufabujogiretimusaf.pdfIn PDF document text
- https://s3.amazonaws.com/waxapoz/701171426.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc0dd745bcb0228a2824d01/t/5fc491e9e18c5c478e8d7602/1606717929851/english_essentials_answer_key.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc28802bda9c57a97c88755/t/5fc79d7e3d56556d14433895/1606917503851/vox_cinema_abu_dhabi_menu.pdfIn PDF document text
- https://static1.squarespace.com/static/5fdd539cc66bff209e8009b6/t/5fde74607185ee572d48a2cc/1608414304243/vazinobunubipomupole.pdfIn PDF document text
- https://s3.amazonaws.com/dusined/sitozujezugotanabor.pdfIn PDF document text
- https://s3.amazonaws.com/pizivurapab/bjp4_self-check_answers.pdfIn PDF document text
- https://static1.squarespace.com/static/5fc27abd116eb00e3c55ea17/t/5fd1e62c133bcb3b88a0bb76/1607591470195/download_game_home_design_3d_mod_apk.pdfIn PDF document text
- https://s3.amazonaws.com/lovomijelun/9575390293.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000ba82.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBA82 | 5192 bytes |
SHA-256: 50ae8908498d9525e1f7dd816ac7f161592343cf4a786c89b7ca2135231aa925 |
|||
font_01_sfnt_off0000cc37.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCC37 | 9276 bytes |
SHA-256: 1414a6ad1dabf31ec953bfb182cf22120adf63ca6375dae9c2a68b44780d58ea |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.