MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.link/wix?keyword=palo+alto+firewall+models+pdf'. This indicates the document's primary purpose is to redirect users to malicious infrastructure. The PDF also exhibits characteristics of a link farm, with numerous external links, further supporting the malicious intent. The ML classifier strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=palo+alto+firewall+models+pdf
- https://static.usrfiles.com/ugd/9374a7_799fbf7222e44c72beb206effadf3a12.pdf
- https://static.usrfiles.com/ugd/b8c837_0cd9aa6b21b14e98aed75f44e3f86962.pdf
- https://static.usrfiles.com/ugd/5262df_65eec43552384beda2480f550e7bff22.pdf
- https://static.usrfiles.com/ugd/17ce20_f5e70306acfc433ebf011e7d3c74cecb.pdf
- https://static.usrfiles.com/ugd/c20ea7_7741684ded8f45dbbc12b76e62329de9.pdf
- https://static.usrfiles.com/ugd/8d5d69_995b6ed2f4704ef38f6eafcfc41cfd95.pdf
- https://static.usrfiles.com/ugd/bf07b1_17cb68a334f54ca1ad7bfa6961a8ad28.pdf
- https://static.usrfiles.com/ugd/d90490_7171b6d6e0834e4687a079eb1cdbe2bd.pdf
- https://cdn.shopify.com/s/files/1/0439/4260/9064/files/4372792995.pdf
- https://cdn.shopify.com/s/files/1/0433/8896/0933/files/21690211959.pdf
- https://cdn.shopify.com/s/files/1/0432/1984/5277/files/60064195918.pdf
- https://cdn.shopify.com/s/files/1/0464/2550/5944/files/nenasodifixutibufi.pdf
- https://cdn.shopify.com/s/files/1/0430/1560/2337/files/sijupuvezapisojolakaf.pdf
- https://static.usrfiles.com/ugd/268ab1_be6d05329c5144f897c28808521ce40c.pdf
- https://static.usrfiles.com/ugd/978dd5_a247db3df8a242ceb1a43389f065e1e3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000071c8.bin5be3c1ed6e44ba1f5355a1a40c368320e4b964de4fcc38a01036fee4c23bc5f2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x71C8 | 5280 bytes |
font_01_sfnt_off000083bd.bin502c47aa4e5663ddf6fcd84f3352eeeed18d33bea47ec611a70eacf2925cc584 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x83BD | 12060 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.