Malware Insights
The PDF document was flagged as malicious by a machine learning classifier and contains a critical heuristic indicating a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the URL https://ttraff.ru/wix?keyword=custom+facerig+avatar, which is also listed as a malicious redirector. Additionally, the PDF contains a large number of external links, many pointing to Shopify domains, suggesting a link farm or SEO poisoning attempt, with the primary malicious link being the ttraff.ru domain.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=custom+facerig+avatar
- https://static.usrfiles.com/ugd/b8c837_6797cc100474482bbaf7bc7ea767e960.pdf
- https://static.usrfiles.com/ugd/804ff6_ded916c4ec8e42e3a8f89092b7495e5d.pdf
- https://static.usrfiles.com/ugd/837d34_36fcb2a634664ef18b1f2e922b2686ab.pdf
- https://cdn.shopify.com/s/files/1/0434/0154/3831/files/convert_seconds_to_hours.pdf
- https://cdn.shopify.com/s/files/1/0429/3532/0735/files/notasetafemo.pdf
- https://cdn.shopify.com/s/files/1/0429/5737/3589/files/30160611883.pdf
- https://cdn.shopify.com/s/files/1/0431/9179/5873/files/bimitasezofososibebamos.pdf
- https://cdn.shopify.com/s/files/1/0428/3822/9158/files/zabizebizuxefaf.pdf
- https://cdn.shopify.com/s/files/1/0429/2801/3471/files/6880369610.pdf
- https://cdn.shopify.com/s/files/1/0434/4188/1253/files/kazuti.pdf
- https://static.usrfiles.com/ugd/57c819_77175cf313124124ab9348132ee3f370.pdf
- https://static.usrfiles.com/ugd/ed64d2_fea8b1db63cb43489e5680b01d27e4b3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005649.bin1e23c5b35149eb533ab29e2d3facce9403875bf0f6aa33672bdb656153e28f57 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5649 | 4832 bytes |
font_01_sfnt_off0000673e.binfac2e1047bfd7e1af652c31d558b983f949addd71b55fe6661e2b73ec013b64a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x673E | 5132 bytes |
font_02_sfnt_off000078a5.bin7ca60493e9e76ace5b532f84d8460797968f01ce4c7f6e40a32799cb6476d770 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x78A5 | 10656 bytes |
font_03_sfnt_off00009d43.binc3d0ee408bee49a88931d2ac630a9fb52e88a46fabab5a72aa19e78bbe1d3826 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9D43 | 16376 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.