Malware Insights
This PDF file was identified as malicious by an ML classifier and contains a large number of embedded links, many pointing to disposable hosting services. One critical heuristic indicates a direct link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains URLs that are also present in the list of embedded links, suggesting a coordinated effort to redirect users to malicious sites. The primary attack pattern appears to be the creation of a link farm designed to distribute malicious content or phish users.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/strik?keyword=rss+feed+cnn+arabic In PDF document text
- https://cdn-cms.f-static.net/uploads/4426090/normal_5f97826ab98be.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369316/normal_5f891007555f8.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4403119/normal_5f9768f6143c7.pdfIn PDF document text
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/vowusogizidamodekog.pdfIn PDF document text
- https://jasazifo.weebly.com/uploads/1/3/1/4/131437377/3953438.pdfIn PDF document text
- https://xonuvalax.weebly.com/uploads/1/3/1/4/131437330/gisilolozelid_wurerowipapawiw_kowudakexifazi_fepegekob.pdfIn PDF document text
- https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/8e3e1.pdfIn PDF document text
- https://mujetuzavos.weebly.com/uploads/1/3/4/2/134266282/8574754.pdfIn PDF document text
- https://nulixedupalaz.weebly.com/uploads/1/3/0/7/130739510/a78475a4aaebd4.pdfIn PDF document text
- https://famotufenimuz.weebly.com/uploads/1/3/4/1/134132127/76b72cd44.pdfIn PDF document text
- https://lotagixowila.weebly.com/uploads/1/3/1/1/131164100/f9c933793ed8f.pdfIn PDF document text
- https://mogezisatizate.weebly.com/uploads/1/3/0/7/130775403/8569445.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4403565/normal_5f918dbf8ac5f.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4374686/normal_5f8e21b991a1d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4403560/normal_5f9597c55ee11.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/106b7bc9-b7e0-467b-b517-aa1373fdf56b/unos_dos_tres_quattro.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0264e12e-a35d-4a67-9298-7f5f4217ae89/53174461066.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c952fccf-465a-497a-a7d7-4278e3a0c077/rawelewuzizeselaj.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c19b25f1-9c29-4a6f-86ca-f538ab1ad762/wamepotefamow.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/045c11a3-4235-4fa6-9e02-3fbb962403f7/11004943644.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0500/5328/4008/files/baixar_dicionario_portugues_espanhol.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0498/6948/8280/files/state_of_georgia_vs_rick_allen_rick_and_morty.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0499/2162/2184/files/49071406004.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0499/8434/0118/files/cintiq_21ux_dtk-2100_manual.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000063dd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x63DD | 5128 bytes |
SHA-256: 1b53dbe8126d5daa39820c7b7875478d689a89c8057ab47d368260a485331016 |
|||
font_01_sfnt_off00007553.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7553 | 10748 bytes |
SHA-256: 3fa81e573d4ad106eb584aa9a1c685eca4bba8a682392c0469b50f7ac9fc147b |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.