MALICIOUS
74
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file contains heuristics indicating it is malicious and uses an image lure to redirect users to an SEO redirector. The primary URL identified, 'https://trafffe.ru/strik?keyword=warriors+a+dangerous+path+pdf+free', is associated with phishing or malware distribution. Although no scripts were explicitly extracted, the PDF structure and embedded links suggest an attempt to lure users to a malicious site, likely as part of a phishing campaign.
Machine Learning
- Nyx PDF Classifier malicious score 0.9954
Heuristics 3
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafffe.ru/strik?keyword=warriors+a+dangerous+path+pdf+free PDF link annotation
- https://rofetavagamufup.weebly.com/uploads/1/3/4/3/134373504/zakasojepo_gikokumudigu_babuxopikele.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366035/normal_5f8746e6ab82b.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369520/normal_5f91ba766a54e.pdfIn PDF document text
- https://gejatovuri.weebly.com/uploads/1/3/1/4/131406669/faxenisurasasu-narotonibal.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4409098/normal_5fa2ab5811c5b.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4367920/normal_5f887607e41e2.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/70429488-1487-4c5b-b165-ddddc6af0ae9/bogaxevimukaludu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5c205cb1-8d4a-430e-bd27-dff8772e523c/nl_simyaclar_kimlerdir.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1af3182d-137e-46ff-9306-45c51c56faaf/young_thug_beautiful_thugger_girls_t.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.