MALICIOUS
102
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a link disguised as a download button, which redirects to a malicious URL. The ML classifier strongly indicates maliciousness, and the embedded URL is flagged as a known malicious redirector. No scripts were extracted, but the document's structure and embedded link suggest a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/pify?keyword=fate+the+game+free+online+no+download In PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/9b5c0087-f072-45bb-af37-256239ac2f09/nusupiger.pdfIn PDF document text
- https://s3.amazonaws.com/zirojopemup/lafozamubowitabolo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e2b9b337-ef93-49a8-9ead-2f145364a64b/bonakowikuxavojovemelexu.pdfIn PDF document text
- https://s3.amazonaws.com/begijufadi/55712346329.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/eee97398-8291-482c-93e5-b4466920aa64/building_spelling_skills_grade_3_worksheets.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ad1b31bc-197f-41ff-9198-fc045930c3c3/908587095.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/13dc3456-f0a9-4217-8ee1-623d925d4328/kingdom_come_deliverance_best_light.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4a799a11-d30a-4c46-a829-5d8c2c8850fe/3174523693.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/84851f52-0b44-4e38-a8b4-c4ab2e323f77/talixolesifijale.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9b4c830c-6163-403b-b834-6d98f6902633/nclex_questions_and_answers_made_incredibly_easy.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e688ad4e-3397-4f44-976a-a522fdb494af/patton_space_heater_manual.pdfIn PDF document text
- https://s3.amazonaws.com/subud/how_to_reduce_file_size_macbook_air.pdfIn PDF document text
- https://s3.amazonaws.com/lulelepese/70741473391.pdfIn PDF document text
- https://s3.amazonaws.com/zirojopemup/teardrop_banner_template.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/01c7dcd9-f871-4859-a8b7-68758a858b2b/1766873180.pdfIn PDF document text
- https://s3.amazonaws.com/lupebesu/40653814142.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6739cf52-2630-4342-8837-2c4e24885e4e/12758585804.pdfIn PDF document text
- https://s3.amazonaws.com/mupukesunobaga/cambridge_checkpoint_science_coursebook_7_download.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/26c642f8-17ee-4ce8-8636-bb0c7a78a4fe/58101568671.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000712b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x712B | 5188 bytes |
SHA-256: 72bbde30e9f7bd7fbff851930702763a3cd89358cdd4508d07fbbfdcab484121 |
|||
font_01_sfnt_off000082bd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x82BD | 12016 bytes |
SHA-256: 29f2ed3fc90af32579796dd6bda5f3a08b5170009f9a156c6074f7f886ab59c3 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.