MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a link to a known malicious redirector, ttraff.com, which is disguised as a download link for '3d movies gear vr'. The document body, though heavily obfuscated, contains the same lure text and URLs. The presence of a large number of external PDF links, many pointing to static.usrfiles.com, suggests a link farm or SEO poisoning tactic to increase visibility of the malicious redirector.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=download+3d+movies+gear+vr
- https://static.usrfiles.com/ugd/b8c837_86c9a4350dd940938455b2054075c08f.pdf
- https://static.usrfiles.com/ugd/6cf392_9af3db97fd4e4e4eb23d4db6b905a327.pdf
- https://static.usrfiles.com/ugd/b8c837_00f12b5f256a46199567452546e0d61c.pdf
- https://static.usrfiles.com/ugd/b8c837_50bab3f08c394066abee1ec8615017ce.pdf
- https://static.usrfiles.com/ugd/5ecadc_4a327d25c03b4ae6ae327d30a736449d.pdf
- https://static.usrfiles.com/ugd/de60da_25919486669346f192817bce97e63b3a.pdf
- https://static.usrfiles.com/ugd/b8c837_dad603711759498baecad27aba6bcb64.pdf
- https://static.usrfiles.com/ugd/b8c837_d4596a7deb9a4e2b80d4de45785102e6.pdf
- https://static.usrfiles.com/ugd/b8c837_034fe068f00c4feab4e6424493976977.pdf
- https://static.usrfiles.com/ugd/71fd01_4b2503d48a6349cab06f33909ff514c2.pdf
- https://static.usrfiles.com/ugd/b8c837_fb535a3769be4c5fbdc1600a9f909bca.pdf
- https://static.usrfiles.com/ugd/b5aed9_ec97888ecc4449598d6df6c06280b39c.pdf
- https://static.usrfiles.com/ugd/4b7290_9cbbb6ff0f9c4d8fb539c22af86c6759.pdf
- https://static.usrfiles.com/ugd/b5472a_37455df8540e4ad78998cd48527bfcec.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000060ac.bin1815ac4d104f8054845b09b10d1d01d32e57a78bdd2a948b051a1e9322de2620 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x60AC | 5168 bytes |
font_01_sfnt_off00007230.bin32a41bb34bd0c2ca1776bdb170b2cc8969d0c1bd0a276c2529f71a65b9fee790 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7230 | 10752 bytes |
font_02_sfnt_off0000966a.bin9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x966A | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.