MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a mass of external links, many pointing to Shopify, but one critical link redirects to a known malicious domain. The document body, though heavily obfuscated, contains text related to 'Halloween food label templates free' and the malicious URL. This suggests a social engineering lure to drive traffic to a malicious site, likely for further exploitation or phishing.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=halloween+food+label+templates+free
- https://cdn.shopify.com/s/files/1/0437/5832/1818/files/neoliberalismo_america_latina.pdf
- https://cdn.shopify.com/s/files/1/0434/4070/1606/files/columbus_dispatch_voting_guide.pdf
- https://cdn.shopify.com/s/files/1/0439/3969/2699/files/befakibosezowuzejitazana.pdf
- https://static.usrfiles.com/ugd/b8c837_8c7fedc56ae14cd1a0b5a23f58cdc1f3.pdf
- https://static.usrfiles.com/ugd/cc03df_2de50500e23f4ed18668c2961f26498a.pdf
- https://static.usrfiles.com/ugd/74c34a_2e9645a0aca1487087d7a00e175d451a.pdf
- https://static.usrfiles.com/ugd/0c268c_2014fc9e38a24ce9b1467d29ca22793d.pdf
- https://static.usrfiles.com/ugd/2c8d66_b2ab0d45bb9640e2a333b372bc51688c.pdf
- https://static.usrfiles.com/ugd/2f3ac6_31a0aee6dab2441e81c821650031f98b.pdf
- https://static.usrfiles.com/ugd/96768c_98735b300b5049b2990915c155bd0480.pdf
- https://static.usrfiles.com/ugd/ede58b_49601cc51c844db285b267880cbba7a4.pdf
- https://static.usrfiles.com/ugd/599026_8cd78e1af0d64d1d953ec5f475a1efbe.pdf
- https://static.usrfiles.com/ugd/1e533a_9bcb603fb4e44a45b62a7708603c4039.pdf
- https://static.usrfiles.com/ugd/0779a3_83d71ed0110c4085868ece219a16b9dd.pdf
- https://static.usrfiles.com/ugd/a382ee_ba6c2360ef634aad89dee9e6a566939a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007034.bin1181be580467dad004c8f3abd2ba3fa1248ef2bf6830ad74a0dcf8601d60e07e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7034 | 5380 bytes |
font_01_sfnt_off00008278.binb25fe81dd22fd04660fa11e709edc1289efee58fc41bc433188d7b9aa4419048 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8278 | 10772 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.