MALICIOUS
204
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document contains a large number of embedded links, many of which point to disposable hosting and redirect to malicious infrastructure. The document body, though heavily obfuscated, contains a URL that appears to be part of a phishing lure related to employment opportunities. The presence of numerous links and the redirection to a known malicious domain strongly suggest a campaign to drive traffic to malicious sites, likely for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 6
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=canton+central+school+ny+employment In PDF document text
- http://files.activetwa.org/uploads/1/3/1/4/131438583/ea8bd71.pdfIn PDF document text
- http://files.tanyardcreekranch.com/uploads/1/3/1/4/131453984/gulugubifo.pdfIn PDF document text
- http://files.inneractiondance.com/uploads/1/3/1/8/131858661/9627550.pdfIn PDF document text
- http://files.shockentertainmentinc.com/uploads/1/3/1/8/131871745/239b8dbae0c1.pdfIn PDF document text
- https://forms.sllboces.org/Forms/CommonApplicationIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://24f5931b-92e9-44d1-8877-b9ccb7e0a962.filesusr.com/ugd/09c3c7_8f002997965b484ba689e9edef2ddca0.pdf?index=trueIn PDF document text
- https://685d7a13-cd98-4f1d-b01f-999bdf3dc6a5.filesusr.com/ugd/b4f0c6_ff3e1ea42e60491183f9126b6abdc8f6.pdf?index=trueIn PDF document text
- https://402f1ab5-5c8c-41c0-ac27-0d53d993ffb8.filesusr.com/ugd/daca0d_2b53500797dd4660819873f6e64835b6.pdf?index=trueIn PDF document text
- https://1696b0bd-e2ed-40f4-acc2-9dadb4e8812a.filesusr.com/ugd/bdc04d_ed9d49fd1fbb4958b2aa13bab578b1ad.pdf?index=trueIn PDF document text
- https://0b8184c7-df70-425e-af83-76d5d2ab3a73.filesusr.com/ugd/756799_1995bedf4f08481bb3089a5fe6cf98e2.pdf?index=trueIn PDF document text
- https://496735f9-910a-4c18-90bb-8041be36d028.filesusr.com/ugd/c8d394_61ed5357e08a416ab1d708dc1f027dcf.pdf?index=trueIn PDF document text
- https://d7fb84c8-6580-4170-b5a7-77855172c022.filesusr.com/ugd/c1108c_d1539fa083e94fae9f016591b569a39e.pdf?index=trueIn PDF document text
- https://9e4de096-f7a8-40c2-a63f-d51f03b91a58.filesusr.com/ugd/d6af85_bb1d03f075e14b0cb9742edb10c60a40.pdf?index=trueIn PDF document text
- https://cdn.shopify.com/s/files/1/0435/2793/0011/files/80998474297.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0429/9925/1093/files/2139421792.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0432/6467/1906/files/managerial_economics_samuelson.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
🗂 Part of campaign:
activetwa.org
3 samples
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000b223.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB223 | 5180 bytes |
SHA-256: 5b7dcd52dbb1d7b688e5088bc1f2eec1e1836f7760eed02f27fd8a641f10afeb |
|||
font_01_sfnt_off0000c396.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC396 | 10844 bytes |
SHA-256: cdb61aeac5b89faef19536c6261ab58221f178fb3a672db60d98312bfd1defca |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.