MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a critical heuristic firing for linking to a malicious redirector, which is also present in the document body. The PDF also contains a large number of external links, suggesting a link farm or SEO poisoning attempt. The ML classifier strongly indicates maliciousness. The embedded URL is the primary indicator of malicious intent, likely leading to a phishing or malware download site.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/123?keyword=block+all+restricted+calls+android
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/fejatepudopito/62670747559.pdf
- https://s3.amazonaws.com/wonoti/eduardo_galeano_el_libro_de_los_abrazos_gratis.pdf
- https://s3.amazonaws.com/xanebavifamopez/kizosexov.pdf
- https://s3.amazonaws.com/tesodagiwor/filotisoladubulobiba.pdf
- https://s3.amazonaws.com/rowubunak/meluremuvazetexumiro.pdf
- https://s3.amazonaws.com/memul/mewukefokepusogi.pdf
- https://s3.amazonaws.com/magapeguwabe/64952105701.pdf
- https://s3.amazonaws.com/sugaguxagu/20863842535.pdf
- https://s3.amazonaws.com/bisegilupuf/jeevan_umang_brochure.pdf
- https://cdn.shopify.com/s/files/1/0431/9241/8468/files/55699262345.pdf
- https://cdn.shopify.com/s/files/1/0266/7787/0786/files/201_knockout_answers_to_tough_interview_questions.pdf
- https://s3.amazonaws.com/pazifetanegapu/gasukatovezolowizapipav.pdf
- https://s3.amazonaws.com/dobesogum/kixajilifamuwijuze.pdf
- https://s3.amazonaws.com/subud/35599353420.pdf
- https://s3.amazonaws.com/juvetaso/jekitogegogurivuba.pdf
- https://s3.amazonaws.com/vavebufevodutob/padunodo.pdf
- https://uploads.strikinglycdn.com/files/0a68e5a9-1747-442e-9aec-c41f7e1c77f0/the_graveyard_book_summary.pdf
- https://uploads.strikinglycdn.com/files/326ab23c-a383-4475-afa0-9799b588c871/blue_dragon_guide_heroes_guild.pdf
- https://uploads.strikinglycdn.com/files/2d7858aa-98bf-466a-a97d-258507b32ea2/30072605601.pdf
- https://uploads.strikinglycdn.com/files/81d5345f-be4f-4886-8c1a-0c9ff7f69d82/5172338083.pdf
- https://uploads.strikinglycdn.com/files/0a1e4bc0-f1ce-42a1-a917-bb4773b2608d/sinozabemozizitibonimu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008124.bin58040034d9a45eb7810115ed172137aa9faa5085280ca3a3fc2fae4323186e5b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8124 | 2996 bytes |
font_01_sfnt_off00008be2.bin06953db4546504fe6e19c22b5b9a9aa9c46dd2940f9af9d7458d9d36f914b358 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8BE2 | 5044 bytes |
font_02_sfnt_off00009d0c.bindc4aac0b7fbf2e3119a0893097beb62a5bb8f80316d26155635af430a78cbd40 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9D0C | 11412 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.