MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF sample was flagged by multiple critical heuristics, including PDF_MALICIOUS_REDIRECTOR_LINK and PDF_SEO_LINK_FARM, indicating it is designed to host a large number of links. The primary malicious URL identified is https://ttraff.com/wix?keyword=harry+potter+20th+anniversary+editio, which likely serves as a redirector to further malicious content. The presence of embedded URLs and the ML classifier's high confidence score support this assessment.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=harry+potter+20th+anniversary+editio
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://cdn.shopify.com/s/files/1/0433/5878/1590/files/ar_rahman_music.pdf
- https://cdn.shopify.com/s/files/1/0432/6470/4662/files/43031987041.pdf
- https://cdn.shopify.com/s/files/1/0432/8646/2628/files/93458104178.pdf
- https://cdn.shopify.com/s/files/1/0434/2333/4565/files/lodijotobobezoxeb.pdf
- https://cdn.shopify.com/s/files/1/0432/2908/5859/files/hfsa_heart_failure_guidelines.pdf
- https://static.usrfiles.com/ugd/43d598_58204c9494de44cdb2bfbf1a27a2f7a9.pdf
- https://static.usrfiles.com/ugd/158fb9_6506fe5f439a46b3bb0a9e9f4c32e8ce.pdf
- https://static.usrfiles.com/ugd/93971e_f1c92649bec34a4981d25b7675b50b72.pdf
- https://static.usrfiles.com/ugd/b8c837_9a3b37f170d244a4b7b7ee49d1f1d659.pdf
- https://static.usrfiles.com/ugd/23e9be_d82e984451a54047ba8effc89363ffa2.pdf
- https://static.usrfiles.com/ugd/f967ac_99a66376e8f94bfabe80e8f1d3fdb7ea.pdf
- https://static.usrfiles.com/ugd/c068f8_596a541fdb554b358e3965e6630c6f1b.pdf
- https://static.usrfiles.com/ugd/1df9ea_05b0360f7b794c879f945eb53595835e.pdf
- https://static.usrfiles.com/ugd/9cfd0a_90f1fd03b7534347a2201a06b3cabb1f.pdf
- https://static.usrfiles.com/ugd/b8c837_b19ae811a6e5425888552086771aff93.pdf
- https://static.usrfiles.com/ugd/162fe6_d5202ea192f34e1ba29e1def74be7902.pdf
- https://static.usrfiles.com/ugd/b8c837_eb6fca7f18444a6a859001c0166b6698.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000066f1.bin09b81c0d1291aaa31967b735ca7a0a61a4f97d8962eb9addd4532cf9215fe63c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x66F1 | 5412 bytes |
font_01_sfnt_off0000795a.bin60e35122e23a81e9317b80e791d2996ee0c1bfd7f70b72a5a04572a43eb91cbc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x795A | 10508 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.