MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a link to a known malicious redirector, ttraff.cc, disguised as a legal document template. This suggests a phishing attempt to lure users to malicious infrastructure. The PDF also hosts a large number of external links, many pointing to static.usrfiles.com, which is flagged as a link farm. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=deed+of+appointment+of+trustee+template+nz
- https://static.usrfiles.com/ugd/bc0d1e_b2c0dfe3be6643e5bd8c0eef670002b9.pdf
- https://static.usrfiles.com/ugd/d2057d_f6fce7ff966042e0ba8d4688d3ac1fd2.pdf
- https://static.usrfiles.com/ugd/f3ecbe_7be76fa6a0174bb6995c38e8df98e20a.pdf
- https://static.usrfiles.com/ugd/2072cd_a1c9ac75e4544b01846ce50d1be27db2.pdf
- https://static.usrfiles.com/ugd/895bef_9005679cb3e34122927b57cbfc6fd8b5.pdf
- https://static.usrfiles.com/ugd/384ea4_e50d95b930604458be8018d177cf3358.pdf
- https://static.usrfiles.com/ugd/1a89c8_3cc04a6edd7e4ca2b2ea7f972900146b.pdf
- https://static.usrfiles.com/ugd/30e015_59008c2b3ab4419dbdc7797afabe211c.pdf
- https://static.usrfiles.com/ugd/b8c837_31e591a6907047dc93217a5834b16001.pdf
- https://static.usrfiles.com/ugd/1e32c2_884f41a5fa4f4aa79951b022eb7a90b7.pdf
- https://static.usrfiles.com/ugd/99965f_51765db94f324090ab629c446c742e40.pdf
- https://static.usrfiles.com/ugd/ebc5f9_e082b07ae00840109b453deff927ecb5.pdf
- https://static.usrfiles.com/ugd/64d889_db7edba39382468d9afed76ede9c385e.pdf
- https://static.usrfiles.com/ugd/87a178_37ad028b3b5e4e91aacc93cb16dec607.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006137.binbfc05478dd5c9e6bff0690277b54d833b9e1e2dd68cb3cdbf7ac0c5e9f1e1d3f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6137 | 5236 bytes |
font_01_sfnt_off00007300.binf81bc6c8ea5d9806cd63a188dc76918cf743192d5c98ed9e5afe0a95d58bd6a1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7300 | 11520 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.