MALICIOUS
192
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous links designed to appear as free downloads, including a prominent link to 'gettraff.ru' which is flagged as a malicious redirector. The document body, though heavily obfuscated, contains text related to "Textbook of virology pdf free download" and the malicious URL, indicating a phishing or scam attempt. The presence of multiple links to external PDFs, many hosted on platforms like Strikingly and Weebly, suggests a link farm designed to drive traffic to malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9988
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/123?keyword=textbook+of+virology+pdf+free+download In PDF document text
- https://pojutawetuje.weebly.com/uploads/1/3/1/3/131382470/sotekumubagowuwujim.pdfIn PDF document text
- https://xavoxoxuda.weebly.com/uploads/1/3/1/3/131379246/b8092.pdfIn PDF document text
- https://gonerogad.weebly.com/uploads/1/3/1/4/131438616/2918a3f088f4.pdfIn PDF document text
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/pudojupusovutaf.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4382770/normal_5f8da7844611f.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4367964/normal_5f87f0ae43ff4.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4388413/normal_5f8e0f4726234.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366359/normal_5f870eff152d4.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4367281/normal_5f89bc62e25f3.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4389085/normal_5f8dc75267116.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366032/normal_5f8721894f0ed.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366044/normal_5f8cf9c6a7799.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4385869/normal_5f8dfc4162c83.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/037d1322-0180-4bd1-a278-b689992b8bc7/bumimu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d6a09c51-2a6e-4e35-bea0-2b12169c983b/ligapikelowofekotuguteba.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a28e329c-7c04-46e8-a3b1-3c5363b8bafb/64713818350.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5a267305-a266-4d6b-9004-a2cc4de6f4ac/2787964250.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2f967401-0c7a-4c62-ad03-f9922ecee328/zanutejapadus.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2e265f94-3ad6-4a7b-a1a9-1af1319a89ef/kipaxobavofigoviruvasaf.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/683beb14-64ea-43ad-9902-bc6436052dae/27051522431.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/642c054b-69a9-489f-b4c6-26d67b89695a/guzipaw.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/52352bd8-d384-4ae0-9a25-7f954b79729d/pejanisuteripotuterun.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/46c9e468-49e1-4daf-806e-ec006f64b4ef/xonebovosinifivulelowo.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0cc3f72f-46de-4199-a61c-2e4cdb102b1b/febixorono.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/24a13083-92b6-41e9-8bf2-efac1463bc9a/51956683302.pdfIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000621b.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x621B | 5504 bytes |
SHA-256: ba6f4f42353425402599be5c0f7146b9706d31bd76a72878ef16d27d92341917 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.