MALICIOUS
242
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
T1203 Exploitation for Client Execution
This PDF file exhibits multiple high-risk heuristics indicating malicious intent. It contains a link to a known malicious redirector, https://ggtraff.ru/123?keyword=manisha+mam+3000+root+words+pdf+download, and employs social engineering tactics like a 'download button' lure and a browser extension installation lure. The ML classifier also strongly flagged this PDF as malicious. The primary goal appears to be directing the user to malicious infrastructure.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 7
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Browser extension / update installation lure high SE_BROWSER_INSTALL_LUREDocument tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/123?keyword=manisha+mam+3000+root+words+pdf+download In PDF document text
- https://cdn-cms.f-static.net/uploads/4369168/normal_5f884dc411a7e.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366055/normal_5f872ea97a3af.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4374682/normal_5f8949f18996f.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4375908/normal_5f89e2d3e73d0.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369308/normal_5f87e25588583.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4367290/normal_5f88fcd1e5f94.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366008/normal_5f8bf58e1a3d9.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4372358/normal_5f89152737390.pdfIn PDF document text
- https://nulixedupalaz.weebly.com/uploads/1/3/0/7/130739510/2a7dc61a1847d.pdfIn PDF document text
- https://mefemanodi.weebly.com/uploads/1/3/1/4/131454269/9c21a3129791d.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://cdn.shopify.com/s/files/1/0433/6680/9765/files/gorokebivefana.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0463/4456/8989/files/cyclops_hull_fragments.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0484/8907/0747/files/death_flower_sims_4.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0498/8105/5390/files/33914556694.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0485/3301/2635/files/vukulidoromotusasadi.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f48fcfde-3a0b-469e-bd82-49f0e965a079/simixusavukixa.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e6cc94d8-8c43-4954-a5d4-b0f6a9d80ec7/xoluwupanuzaxuxazebajidis.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/02b79177-1463-4cae-b0e5-7fd23c41cbcd/game_baldi_mod.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2f89bf91-5f43-4de8-a2c4-32effcaae311/fumagirigozibogezifonusez.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1c3fdfae-1ba7-4f62-9051-d604a10f1434/94318187067.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e6848c06-9934-4765-b4c7-604de8cedd6f/bokunedurakifupeleluzek.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c385cfed-2311-4a17-b24c-4edfa0b28f2b/jeremowijib.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00009bc6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9BC6 | 5684 bytes |
SHA-256: 8b6943033009dc0b167996bc7e3f3c52faf434cec5204746d319607e47787eae |
|||
font_01_sfnt_off0000aef4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAEF4 | 10704 bytes |
SHA-256: f0ded9a93b72b1083370e007d7f1ced5b18ca37711e2b060232b7119cf912d7f |
|||
font_02_sfnt_off0000d39a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD39A | 16164 bytes |
SHA-256: ead7fd593d7f5feef6f283420e9b55f8fa4552f107c64b0063d474dd3355abd8 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.