MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a significant number of embedded links, with one identified as a malicious redirector. The document body, though heavily obfuscated, contains references to software names and URLs, suggesting a lure. The heuristic firings confirm the presence of a malicious redirector and a large link farm within the PDF, indicating an attempt to drive traffic to potentially harmful sites. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=foxit+phantompdf+free
- https://static.usrfiles.com/ugd/b8c837_93241c886a3e4ff28d10ec4dead6cf3e.pdf
- https://static.usrfiles.com/ugd/87a178_339c392079c640698db36f0bd85ff69e.pdf
- https://static.usrfiles.com/ugd/1f6d71_afa4c2c1f0874d528d3328053e838433.pdf
- https://static.usrfiles.com/ugd/b8c837_edda605b7c2e48e6832091829f7ad355.pdf
- https://static.usrfiles.com/ugd/b8c837_51a779df1f9348c3967d9a86dfea61fc.pdf
- https://static.usrfiles.com/ugd/b8c837_4d0dcc6942254291ad08b1dd63b43c85.pdf
- https://static.usrfiles.com/ugd/b8c837_6856c0cdcb6f437490f3127a4ce77cb9.pdf
- https://static.usrfiles.com/ugd/affb4a_ace6c03426b84bf28b050d5d1541bc09.pdf
- https://static.usrfiles.com/ugd/defcb2_da2e42765ec24a90a0e5d8f1fdc669ae.pdf
- https://static.usrfiles.com/ugd/7598fa_826a381683e24ebc9c5fde853e70d280.pdf
- https://static.usrfiles.com/ugd/73cb9e_883b647e97384236ab01bd14c7301868.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tufajotojitumawudawemir.pdf
- https://cdn.shopify.com/s/files/1/0438/0560/6049/files/python_string_format_named_arguments.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/58580374151.pdf
- https://cdn.shopify.com/s/files/1/0430/1848/5923/files/23761275108.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_005_off0000a220.bina59adf94c644faf8e52e81e9e2e1d082295aa18dfd1f9ad4ae4630b56b4815f6 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xA220 | 28244 bytes |
font_00_sfnt_off00006e1f.bin73a204e38007c895f21a7dcfed527c54522ad743dad058ff766285321c742f48 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6E1F | 5096 bytes |
font_01_sfnt_off00007f46.bina27cfee93495078ef3fd0244bd5c77d74eed770d2fa5c9048900a3509b35477b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7F46 | 10080 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.