MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous embedded links, with one identified as a known malicious redirector. The document body, though heavily obfuscated, contains text related to the embedded URLs, suggesting a lure to external malicious sites. The presence of multiple PDF links points towards a link farm or SEO spam campaign, potentially leading to phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/pify?keyword=1911+tungsten+guide+rod In PDF document text
- http://files.litvaklab.org/uploads/1/3/0/7/130739570/wapajelevedidil.pdfIn PDF document text
- http://wezev.evansmemorialcamp.org/uploads/1/3/1/3/131398243/rajokotepoj-bodud-nizapej-vovupize.pdfIn PDF document text
- http://nipumuxi.chongai520.com/uploads/1/3/1/0/131070381/99e20517385.pdfIn PDF document text
- http://muwef.incurableblog.com/uploads/1/3/1/4/131483234/fcbf8d.pdfIn PDF document text
- http://files.drycreekdesign.net/uploads/1/3/1/8/131871653/56f9a.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/2b9277ad-b108-4c46-b37d-992860f7529a/xedawilemazolujafosafu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/31f4621d-006f-43e1-931e-54b54dfebf81/42522875776.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2bb3f844-5179-4a3e-85e5-7a818b5ad4f8/najisunimetotimasuvadebe.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a479d9a0-459c-4495-b20f-e64aa9275f69/kapuresofi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/bf06f343-381c-4f00-9fe4-ff14ad160b3c/fizaxasa.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/95835413-cd8f-49f3-9ea2-d569299496c7/fokivedif.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f7958bc2-c7bb-462d-b103-6797550280e5/tukodudurimipesopivujup.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d3024ade-aa08-42c1-a18e-8e25962fe3ac/mukigojum.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/074df9fb-bc93-446c-afdf-7ad793a8d46a/puzoki.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d12736c8-5a5c-4242-a280-51fc759aa651/nevuzipexiwupikuraj.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a2f23603-f9c1-4a83-a1e8-ce1437a29704/pawasenez.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/44c33577-fa32-43a0-9a5a-5b025695f768/fevosolawugixigituj.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000529b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x529B | 4068 bytes |
SHA-256: 3e2a26937c2eb5d44d3b5a912fe24910cef3098f6978031eda621c3c862677be |
|||
font_01_sfnt_off000060fc.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x60FC | 4864 bytes |
SHA-256: 123a5735856a0eb62065de67df6cb9ad0395dde6dd6c9959c63dc2826c8adb3f |
|||
font_02_sfnt_off00007198.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7198 | 10312 bytes |
SHA-256: 669e6c52f2928e3aa2678feaf00a38df52162962a598a286b7d330e58df965ab |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.