MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of embedded links, many of which point to external resources. One critical heuristic firing indicates that the PDF links to known malicious redirector infrastructure, specifically 'https://ttraff.ru/pify?keyword=annotate+pdfs+in+evernote'. The document body, though heavily obfuscated, also contains this URL, suggesting it's the primary lure. The ML classifier strongly supports the malicious nature of this PDF.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/pify?keyword=annotate+pdfs+in+evernote
- http://desuwawu.xudedesigns.com/uploads/1/3/1/3/131381787/3a44b44180d21a6.pdf
- http://muvow.galaxydawn.com/uploads/1/3/1/3/131383949/manijuxipujop.pdf
- http://files.nancyribi.ch/uploads/1/3/1/3/131381003/580fa8255.pdf
- https://cdn.shopify.com/s/files/1/0430/8199/0293/files/analyzing_architecture_simon_unwin.pdf
- https://cdn.shopify.com/s/files/1/0431/5765/1613/files/anfitrion_plauto.pdf
- https://cdn.shopify.com/s/files/1/0429/7857/4490/files/20535995253.pdf
- https://cdn.shopify.com/s/files/1/0438/3368/8226/files/fuledemegerukun.pdf
- https://cdn.shopify.com/s/files/1/0434/6226/2936/files/bovad.pdf
- https://cdn.shopify.com/s/files/1/0437/7221/5448/files/30711242521.pdf
- https://cdn.shopify.com/s/files/1/0432/1676/5087/files/android_listview_arrayadapter_viewholder.pdf
- https://cdn.shopify.com/s/files/1/0440/5588/8022/files/lexozevinubu.pdf
- https://cdn.shopify.com/s/files/1/0436/1935/2740/files/guia_de_adestramento_de_ces_gratis.pdf
- https://cdn.shopify.com/s/files/1/0432/1479/9012/files/riper.pdf
- https://cdn.shopify.com/s/files/1/0431/0971/2021/files/lusitu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006865.bin329e155e2f2e3a06fdc2882c46cf561d962fd3fc07c947c796f316dfc30a0f69 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6865 | 5052 bytes |
font_01_sfnt_off000079a9.bina69fba57721df570196d586087d1a766387a37260e46ba3f53bce21fbc85fc66 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x79A9 | 10620 bytes |
font_02_sfnt_off00009de3.bin2cadb2ae25cea88cb182acc54f62d1c218aef5f2772c4081b94d5d3cddde1204 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9DE3 | 16388 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.