Malware Insights
The PDF contains a large number of embedded links, many of which point to domains associated with link farms and redirectors, indicating a phishing or malicious redirection attempt. The ML classifier strongly flagged this PDF as malicious. The primary malicious URL identified is https://ttraff.ru/pify?keyword=beano%2527+s+meme+song, which is likely used to redirect users to further malicious content. The document body itself contains garbled text but also includes the primary malicious URL and several benign-looking Shopify URLs, suggesting an attempt to disguise the malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/pify?keyword=beano%2527+s+meme+song
- http://files.dmsstem.com/uploads/1/3/1/6/131606453/lotiwepelalupe-togowali.pdf
- http://lovimepij.drnicoledinezza.com/uploads/1/3/2/8/132814900/ca2a6edcb6.pdf
- http://xaboruw.mybutlershop.com/uploads/1/3/2/6/132681579/5364807.pdf
- http://files.accelerateyourdegree.com/uploads/1/3/1/6/131636651/2168396.pdf
- http://jiripo.craigupright.net/uploads/1/3/1/4/131408027/fiziroxokode-dulizeza.pdf
- https://cdn.shopify.com/s/files/1/0434/5459/5224/files/amazing_grace_satb_free.pdf
- https://cdn.shopify.com/s/files/1/0431/4061/2262/files/18512487964.pdf
- https://cdn.shopify.com/s/files/1/0433/5190/0310/files/lurujenazora.pdf
- https://cdn.shopify.com/s/files/1/0437/0425/4615/files/luwakanarukamuferilas.pdf
- https://cdn.shopify.com/s/files/1/0437/6962/6781/files/rosedosuza.pdf
- https://cdn.shopify.com/s/files/1/0434/8307/0629/files/xewojososiniguzakam.pdf
- https://cdn.shopify.com/s/files/1/0431/2386/7805/files/kixojiworasez.pdf
- https://cdn.shopify.com/s/files/1/0448/0447/2992/files/medical_microbiology_laboratory_manual.pdf
- https://cdn.shopify.com/s/files/1/0435/3340/2266/files/71291352954.pdf
- https://cdn.shopify.com/s/files/1/0446/1743/3251/files/khan_academy_mappers.pdf
- https://cdn.shopify.com/s/files/1/0434/1497/8718/files/57714299815.pdf
- https://cdn.shopify.com/s/files/1/0447/2363/4330/files/numuvaluxodefadu.pdf
- https://cdn.shopify.com/s/files/1/0430/1121/1425/files/85804634464.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005cba.bindb0a1b4933b145122ddc2065ea1dc91c9ddf49f18c082b5894fd6ba265805140 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5CBA | 4620 bytes |
font_01_sfnt_off00006c4a.bin52434399aa7ff269c35228cb179c9eaff65d01dba200d671a0ddcf6dde172d36 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6C4A | 10572 bytes |
font_02_sfnt_off0000906d.bince7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x906D | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.