MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document was flagged by multiple critical heuristics for containing malicious redirector links and a large link farm. The primary malicious URL, https://ttraff.ru/wix?keyword=transposon+mutagenesis+pdf, is identified as a known malicious redirector. The document's structure suggests it is designed to lure users to external, potentially malicious, content through a network of embedded links.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=transposon+mutagenesis+pdf
- https://cdn.shopify.com/s/files/1/0432/2813/5591/files/93129093448.pdf
- https://cdn.shopify.com/s/files/1/0434/3952/1958/files/852_country_code.pdf
- https://cdn.shopify.com/s/files/1/0452/4628/3937/files/cfop_guide.pdf
- https://cdn.shopify.com/s/files/1/0429/0537/0787/files/sebuxepijiwafavotar.pdf
- https://cdn.shopify.com/s/files/1/0433/0127/3758/files/bosugowubowutobosaragik.pdf
- https://static.usrfiles.com/ugd/917232_e9c8a9d14aff4fd5a5218e6fedbacd27.pdf
- https://static.usrfiles.com/ugd/314c35_6d84d2e3b67d4910b9ea14d5fa3f6d69.pdf
- https://static.usrfiles.com/ugd/b41a9a_bf24923d3523476f82ab2ec6a2b3eb62.pdf
- https://static.usrfiles.com/ugd/359e64_e7714a3496154f78a93a82ed5161255a.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/32852202686.pdf
- https://cdn.shopify.com/s/files/1/0434/5928/1061/files/kalnirnay_calendar_2020_august.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000077c5.bin04932bcd5f141122bf0ab76355241a536430b2e52e7b86203d44142c9d56a8f2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x77C5 | 5280 bytes |
font_01_sfnt_off000089a1.binbd9b921427f3f07ec3e803d8379620446c4ee2711be8b9dca9534405ee568449 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x89A1 | 15420 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.