MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.club/wix?keyword=transitive+and+intransitive+verb+worksheet'. The document body, though heavily obfuscated, also contains this URL and appears to be a lure related to a 'transitive and intransitive verb worksheet'. The presence of numerous external PDF links, many hosted on Shopify, suggests a link farm or SEO poisoning attempt to distribute malicious content. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=transitive+and+intransitive+verb+worksheet
- https://cdn.shopify.com/s/files/1/0429/9869/4042/files/38735654822.pdf
- https://cdn.shopify.com/s/files/1/0437/7706/5121/files/59490214732.pdf
- https://cdn.shopify.com/s/files/1/0435/5850/2563/files/78774187674.pdf
- https://cdn.shopify.com/s/files/1/0428/6971/9196/files/anki_drive_app.pdf
- https://static.usrfiles.com/ugd/9ff9b8_86bd3b476ea14b3daf775816cd3492a8.pdf
- https://cdn.shopify.com/s/files/1/0428/7696/0924/files/86194190374.pdf
- https://cdn.shopify.com/s/files/1/0435/1364/3167/files/vugosegutidonezo.pdf
- https://static.usrfiles.com/ugd/7baf93_24decd35e31845ff981bc107d93e0199.pdf
- https://static.usrfiles.com/ugd/b8c837_7bcc34a0377846cb9b108c067d771ad2.pdf
- https://static.usrfiles.com/ugd/b8c837_782af9f86f0f42eb96f5965a607cb2f8.pdf
- https://static.usrfiles.com/ugd/b8c837_7d17c65107c94a03ab9226ef1b37f8e8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005278.bin1b98247ea2d1471be7cd8eba99d7effe5b2351a1fcecd9778ad74c60bdb25d70 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5278 | 5184 bytes |
font_01_sfnt_off00006427.bin8b15ead894aa80e413d9a180b2cc1c03712c2f93614e7c8736f013690550bc91 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6427 | 9848 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.