MALICIOUS
76
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
T1204.002 Malicious Link
The PDF file contains an embedded JavaScript stream and a critical heuristic firing for a malicious redirector link. The document body, though heavily obfuscated, contains a URL that matches the malicious redirector. This suggests the PDF is designed to trick the user into clicking the link, likely leading to a phishing or malware download site.
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=kcpe+kiswahili+2018+answers
- http://files.buddiesbooksandbrunch.org/uploads/1/3/1/3/131380619/9194975.pdf
- https://cdn.shopify.com/s/files/1/0434/3191/9765/files/58467245123.pdf
- https://cdn.shopify.com/s/files/1/0430/2965/9805/files/lemijenaguxuxetase.pdf
- https://cdn.shopify.com/s/files/1/0432/5507/0880/files/dasijajo.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tiwimuz.pdf
- https://cdn.shopify.com/s/files/1/0435/2344/0799/files/pinobuwosuseju.pdf
- https://cdn.shopify.com/s/files/1/0427/9864/5404/files/apology_letter_example.pdf
- https://cdn.shopify.com/s/files/1/0434/8418/4728/files/46540259924.pdf
- https://cdn.shopify.com/s/files/1/0432/4953/3088/files/posozorit.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/69440205977.pdf
- https://cdn.shopify.com/s/files/1/0431/5981/4306/files/carbohydrate_in_organic_chemistry.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0005107f.bin641b15c2f799599d5108d383e6d4248340089e9c5c3beb8044d7a23d87f21c2b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5107F | 5664 bytes |
font_01_sfnt_off000523ce.bin45326a4ab6a419d2f30bfcec2f73cf98a56c638e207389405baeddee5b287f21 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x523CE | 16012 bytes |
font_02_sfnt_off0005555e.binfba59e47e8ca233e9d73a8be59979224962753e34c0dd5a07a2b9cc72f79e871 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5555E | 16224 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.