Malware Insights
This PDF document contains a link that redirects to malicious infrastructure, identified by the 'PDF_MALICIOUS_REDIRECTOR_LINK' heuristic. The document also features a link farm of other PDFs, as indicated by 'PDF_SEO_LINK_FARM'. The primary malicious link is 'https://ttraff.com/wix?keyword=queen+news+of+the+world+320kbps+download', which likely serves as a lure to download further malicious content or redirect to a phishing page. No scripts were extracted, but the presence of malicious links suggests an attempt to deliver a payload or phish credentials.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=queen+news+of+the+world+320kbps+download
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cdn.shopify.com/s/files/1/0431/3330/4986/files/27334602152.pdf
- https://cdn.shopify.com/s/files/1/0431/2406/4410/files/29514453505.pdf
- https://cdn.shopify.com/s/files/1/0428/8951/1071/files/fojenumugafakotir.pdf
- https://static.usrfiles.com/ugd/b8c837_362ce055998348668a5072dc3eb203d9.pdf
- https://static.usrfiles.com/ugd/b8c837_9a0d2140dc5c485c8c0658163308a9da.pdf
- https://static.usrfiles.com/ugd/63d3ad_ce5837a102d044f3b0dda9bf0dc580eb.pdf
- https://cdn.shopify.com/s/files/1/0431/9405/6861/files/13457617971.pdf
- https://cdn.shopify.com/s/files/1/0436/3101/8142/files/corporate_finance_10th_edition.pdf
- https://static.usrfiles.com/ugd/79cb75_ddeb3f4771fb47efb1d201d9451f1b57.pdf
- https://static.usrfiles.com/ugd/21e6f2_49a17d39a3aa43ac8a6cf3f3fac6e2a2.pdf
- https://static.usrfiles.com/ugd/06497e_1e6626b391584358826854f53f46013d.pdf
- https://static.usrfiles.com/ugd/3eed2b_d2fe142b36c949068d0eaab49e0b7967.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006b76.bin448ac90484c0181921f5a5d35c0d5755d5d30681aa3efb45362e6015269751d3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6B76 | 5924 bytes |
font_01_sfnt_off00007fa1.bin2d6e746ef12c89a7a82b2deb5662f9fd7b82ab6a3a2ead4411944b5cf6a37694 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7FA1 | 11380 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.