MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains a link to a known malicious redirector, ttraff.cc, which is designed to lead users to malicious content. The document body, though heavily obfuscated, contains the same URL. The presence of a link farm further suggests an attempt to distribute malicious content or engage in SEO manipulation for malicious purposes.
Machine Learning
- Nyx PDF Classifier malicious score 0.9491
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=gaan+bangla+all+song
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://static.usrfiles.com/ugd/e643da_f1f48c33ec484329b210a410357fd071.pdf
- https://static.usrfiles.com/ugd/0010c8_758361d915a14af9b67f181f0ea2ab47.pdf
- https://static.usrfiles.com/ugd/80c1db_45eb356460454504a3274573439ea93b.pdf
- https://static.usrfiles.com/ugd/cfa91a_3d23bcecf06646beb61eb287f2a185b7.pdf
- https://static.usrfiles.com/ugd/0a593f_b0577192a7004b7f83f8894825321f48.pdf
- https://static.usrfiles.com/ugd/50988c_5476a0794d14419491c27ef86f3e749b.pdf
- https://static.usrfiles.com/ugd/55f640_558f687874574550baccab09bdfb236c.pdf
- https://cdn.shopify.com/s/files/1/0463/0750/8381/files/rihanna_we_found_love_indir.pdf
- https://cdn.shopify.com/s/files/1/0438/9571/8040/files/10490176760.pdf
- https://cdn.shopify.com/s/files/1/0428/4963/2415/files/property_damage_incident_report_sample.pdf
- https://cdn.shopify.com/s/files/1/0433/7496/8997/files/vasipikujexatapubun.pdf
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001eb1d.bincc9685a7d0c872b76fccceb18ed42ee44d1ca4f0d448ed1f1bddca898ee95ee6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1EB1D | 4928 bytes |
font_01_sfnt_off0001fbf8.bin35c2f291fd39b6c20f853e2d767d85292607f9cf1875ecb63686e6cdb6653f72 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1FBF8 | 14876 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.